[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1724-1 moodle -- several vulnerabilities

ID: oval:org.secpod.oval:def:600504Date: (C)2011-05-13   (M)2022-10-10
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in Moodle, an online course management system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0500 It was discovered that the information stored in the log tables was not properly sanitized, which could allow attackers to inject arbitrary web code. CVE-2009-0502 It was discovered that certain input via the "Login as" function was not properly sanitised leading to the injection of arbitrary web script. CVE-2008-5153 Dmitry E. Oboukhov discovered that the SpellCheker plugin creates temporary files insecurely, allowing a denial of service attack. Since the plugin was unused, it is removed in this update. For the stable distribution these problems have been fixed in version 1.6.3-2+etch2. For the testing distribution these problems have been fixed in version 1.8.2.dfsg-3+lenny1. For the unstable distribution these problems have been fixed in version 1.8.2.dfsg-4. We recommend that you upgrade your moodle package.

Platform:
Debian 4.0
Product:
moodle
Reference:
DSA-1724-1
CVE-2009-0500
CVE-2009-0502
CVE-2008-5153
CVE    3
CVE-2008-5153
CVE-2009-0502
CVE-2009-0500
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies