Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian 4.0 DSA-1724-1 Critical: Moodle Remote Code Execution Advisory

debian
Calendar Grey February 13, 2009
Debian Logo
Several vulnerabilities in the Moodle platform have been addressed to improve the platform's security and mitigate possible threats.
Several vulnerabilities have been discovered in Moodle, an online course management system

Summary

Several vulnerabilities have been discovered in Moodle, an online
course management system. The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2009-0500

It was discovered that the information stored in the log tables
was not properly sanitized, which could allow attackers to inject
arbitrary web code.

CVE-2009-0502

It was discovered that certain input via the "Login as" function
was not properly sanitised leading to the injection of arbitrary
web script.

CVE-2008-5153

Dmitry E. Oboukhov discovered that the SpellCheker plugin creates
temporary files insecurely, allowing a denial of service attack.
Since the plugin was unused, it is removed in this update.

For the stable distribution (etch) these problems have been fixed in
version 1.6.3-2+etch2.

For the testing (lenny) distribution these problems have been fixed in
version 1.8.2.dfsg-3+lenny1.

For the unstable (sid) distribution these problems have been fixed in
version 1.8.2.dfsg-4.

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: moodle

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here