CVE-2024-25978
published 2024-02-19CVE-2024-25978: Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.94%
57.6th percentile
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| moodle | moodle | >= 0 < 4.1.9 | 4.1.9 |
| moodle | moodle | >= 4.1.0 < 4.1.9 | 4.1.9 |
| moodle | moodle | >= 4.2.0 < 4.2.6 | 4.2.6 |
| moodle | moodle | >= 4.2.0 < 4.2.6 | 4.2.6 |
| moodle | moodle | >= 4.3.0 < 4.3.3 | 4.3.3 |
| moodle | moodle | >= 4.3.0 < 4.3.3 | 4.3.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-25978: Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality
osv·2024-02-19·CVSS 7.5
CVE-2024-25978 [HIGH] CVE-2024-25978: Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
GHSA
Uncontrolled Resource Consumption in moodle
ghsa·2024-02-19
CVE-2024-25978 [HIGH] CWE-400 Uncontrolled Resource Consumption in moodle
Uncontrolled Resource Consumption in moodle
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
OSV
Uncontrolled Resource Consumption in moodle
osv·2024-02-19
CVE-2024-25978 [HIGH] Uncontrolled Resource Consumption in moodle
Uncontrolled Resource Consumption in moodle
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
Suricata
ET EXPLOIT Netgear DGN Remote Code Execution (CVE-2024-12847)
suricata·2021-12-02·CVSS 9.8
CVE-2024-12847 [CRITICAL] ET EXPLOIT Netgear DGN Remote Code Execution (CVE-2024-12847)
ET EXPLOIT Netgear DGN Remote Code Execution (CVE-2024-12847)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Netgear DGN Remote Code Execution (CVE-2024-12847)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd="; fast_pattern; startswith; content:"&curpath=/¤tsetting.htm=1"; endswith; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; content:!"|0d 0a|user-agent|0d 0a|"; reference:url,exploit-db.com/exploits/25978; reference:cve,2024-12847; classtype:attempted-admin; sid:2034576; rev:4; metadata:affected_product Netgear_Router, attack_target Networking_Equipment, created_at 2021_12_02, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag Descriptio
No public exploits indexed.
No writeups or analysis indexed.
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-74641https://bugzilla.redhat.com/show_bug.cgi?id=2264074https://lists.fedoraproject.org/archives/list/[email protected]/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/https://moodle.org/mod/forum/discuss.php?d=455634http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-74641https://bugzilla.redhat.com/show_bug.cgi?id=2264074https://lists.fedoraproject.org/archives/list/[email protected]/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/https://moodle.org/mod/forum/discuss.php?d=455634
2024-02-19
Published