5
CVSSv2

CVE-2011-2772

Published: 15/11/2011 Updated: 12/03/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The get_dataroot_image_path function in lib/file.php in Mahara prior to 1.4.1 does not properly validate uploaded image files, which allows remote malicious users to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.

Vulnerable Product Search on Vulmon Subscribe to Product

mahara mahara 1.0.7

mahara mahara 1.1.0

mahara mahara 1.0.2

mahara mahara 1.0.0

mahara mahara 1.3.0

mahara mahara 1.2.0

mahara mahara 1.1.3

mahara mahara 1.2.4

mahara mahara 1.2.3

mahara mahara 1.1.2

mahara mahara 1.3.5

mahara mahara 1.0.6

mahara mahara 1.1.1

mahara mahara 0.9.2

mahara mahara 1.0.12

mahara mahara 1.0.10

mahara mahara 1.0.13

mahara mahara 1.1.6

mahara mahara 1.2.1

mahara mahara 0.9.0

mahara mahara 1.4

mahara mahara

mahara mahara 1.0.9

mahara mahara 1.0.8

mahara mahara 1.0.3

mahara mahara 1.0.1

mahara mahara 1.3.1

mahara mahara 1.3.2

mahara mahara 1.0.11

mahara mahara 1.1.4

mahara mahara 1.0.14

mahara mahara 1.1.7

mahara mahara 1.1.8

mahara mahara 1.3.3

mahara mahara 1.3.6

mahara mahara 1.3.4

mahara mahara 1.0.5

mahara mahara 1.0.4

mahara mahara 0.9.1

mahara mahara 1.2.6

mahara mahara 1.1.5

mahara mahara 1.1.9

mahara mahara 1.0.15

mahara mahara 1.1

mahara mahara 1.2.2

mahara mahara 1.2.5

mahara mahara 1.3.7

Vendor Advisories

Several vulnerabilities were discovered in Mahara, an electronic portfolio, weblog, and resume builder: CVE-2011-2771 Teemu Vesala discovered that missing input sanitising of RSS feeds could lead to cross-site scripting CVE-2011-2772 Richard Mansfield discovered that insufficient upload restrictions allowed denial of service CVE-2011 ...