CVE-2011-2772

Publication date 15 November 2011

Last updated 24 July 2024


Ubuntu priority

Description

The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.

Status

Package Ubuntu Release Status
mahara 11.10 oneiric
Fixed 1.4.0-1ubuntu0.1
11.04 natty
Fixed 1.2.7-1ubuntu0.2
10.10 maverick
Fixed 1.2.5-2ubuntu0.3
10.04 LTS lucid
Fixed 1.2.4-1ubuntu0.4
8.04 LTS hardy Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
mahara

Access our resources on patching vulnerabilities