First published: Fri Jul 20 2012(Updated: )
CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =1.9.1 | |
Moodle | =1.9.2 | |
Moodle | =1.9.3 | |
Moodle | =1.9.4 | |
Moodle | =1.9.5 | |
Moodle | =1.9.6 | |
Moodle | =1.9.7 | |
Moodle | =1.9.8 | |
Moodle | =1.9.9 | |
Moodle | =1.9.10 | |
Moodle | =1.9.11 | |
Moodle | =1.9.12 | |
Moodle | =1.9.13 | |
Moodle | =1.9.14 | |
Moodle | =2.0.0 | |
Moodle | =2.0.1 | |
Moodle | =2.0.2 | |
Moodle | =2.0.3 | |
Moodle | =2.0.4 | |
Moodle | =2.0.5 | |
Moodle | =2.1.0 | |
Moodle | =2.1.1 | |
Moodle | =2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4586 is classified as a high severity vulnerability due to potential exploitation opportunities for HTTP response splitting attacks.
To mitigate CVE-2011-4586, upgrade your Moodle installation to at least version 1.9.15, 2.0.6, or 2.1.3.
CVE-2011-4586 allows remote attackers to perform HTTP response splitting attacks through arbitrary HTTP header injection.
CVE-2011-4586 affects Moodle versions prior to 1.9.15, 2.0.6, and 2.1.3.
Verify your Moodle version to determine if it is below 1.9.15, 2.0.6, or 2.1.3, which indicates vulnerability to CVE-2011-4586.