CVE-2012-5479

NameCVE-2012-5479
DescriptionThe Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
moodlesourcesqueeze(not affected)
moodlesourcewheezy2.2.3.dfsg-2.6~wheezy0
moodlesource(unstable)2.2.3.dfsg-2.6

Notes

[squeeze] - moodle <not-affected> (Doesn't affect 1.9)

Search for package or bug name: Reporting problems