LWN.net Logo

moodle: man-in-the-middle attack

Package(s):moodle CVE #(s):CVE-2012-6087
Created:January 28, 2013 Updated:April 3, 2013
Description: From the Red Hat bugzilla:

A security flaw was found in the way Moodle, a course management system (CMS), used (lib)cURL's CURLOPT_SSL_VERIFYHOST variable, when doing certificate validation (value of '1' meaning only check for the existence of a common name was used instead of value '2' - which also checks if the particular common name matches the requested hostname of the server). A rogue service could use this flaw to conduct man-in-the-middle (MiTM) attacks.

Alerts:
Fedora FEDORA-2013-0907 2013-01-28
Fedora FEDORA-2013-0968 2013-01-28
Fedora FEDORA-2013-0915 2013-01-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds