Security Advisory

CVE-2011-2772

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-11-15 02:00:00
Last updated 2024-09-17 03:18:11
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.