CVE-2011-4302: Input Validation
mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the opensslverify function, which allows remote attackers to bypass validation via a crafted certificate.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4302?
CVE-2011-4302 has a moderate severity rating as it allows remote attackers to bypass certificate validation.
How do I fix CVE-2011-4302?
To fix CVE-2011-4302, you should upgrade to Moodle version 1.9.14, 2.0.5, or 2.1.2 or later.
What versions of Moodle are affected by CVE-2011-4302?
CVE-2011-4302 affects Moodle versions 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2.
What type of attack can exploit CVE-2011-4302?
CVE-2011-4302 can be exploited by attackers who use a crafted certificate to bypass Openssl verification.
Is CVE-2011-4302 specific to certain operating systems?
CVE-2011-4302 is specific to Moodle installations and is not limited to a particular operating system.