iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial of service (resource consumption) by triggering the calculation of an estimated latitude and longitude for an IP address.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
https://moodle.org/mod/forum/discuss.php?d=275158 | vendor advisory |
http://www.securitytracker.com/id/1031215 | vdb entry |
http://openwall.com/lists/oss-security/2014/11/17/11 | mailing list |
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-47321 | patch |