lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2421-1 | moodle security update |
EUVD |
EUVD-2011-4512 | lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T00:09:19.404Z
Reserved: 2011-11-29T00:00:00
Link: CVE-2011-4587
No data.
Status : Deferred
Published: 2012-07-20T10:40:35.970
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-4587
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD