CVE-2011-1406

Publication date 13 May 2011

Last updated 24 July 2024


Ubuntu priority

Description

Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.

Status

Package Ubuntu Release Status
mahara 11.04 natty
Fixed 1.2.7-1ubuntu0.1
10.10 maverick
Fixed 1.2.5-2ubuntu0.2
10.04 LTS lucid
Fixed 1.2.4-1ubuntu0.3
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release