|
|
| |
|
| |
moodle: man-in-the-middle attack
| Package(s): | moodle |
CVE #(s): | CVE-2012-6087
|
| Created: | January 28, 2013 |
Updated: | April 3, 2013 |
| Description: |
From the Red Hat bugzilla:
A security flaw was found in the way Moodle, a course management system (CMS), used (lib)cURL's CURLOPT_SSL_VERIFYHOST variable, when doing certificate validation (value of '1' meaning only check for the existence of a common name was used instead of value '2' - which also checks if the particular common name matches the requested hostname of the server). A rogue service could use this flaw to conduct man-in-the-middle (MiTM) attacks. |
| Alerts: |
|
( Log in to post comments)
|
|
|