Oval Definition:oval:org.mitre.oval:def:13572
Revision Date:2014-06-23Version:19
Title:DSA-1724-1 moodle -- several vulnerabilities
Description:Several vulnerabilities have been discovered in Moodle, an online course management system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0500 It was discovered that the information stored in the log tables was not properly sanitised, which could allow attackers to inject arbitrary web code. CVE-2009-0502 It was discovered that certain input via the "Login as" function was not properly sanitised leading to the injection of arbitrary web script. CVE-2008-5153 Dmitry E. Oboukhov discovered that the SpellCheker plugin creates temporary files insecurely, allowing a denial of service attack. Since the plugin was unused, it is removed in this update. For the stable distribution these problems have been fixed in version 1.6.3-2+etch2. For the testing distribution these problems have been fixed in version 1.8.2.dfsg-3+lenny1. For the unstable distribution these problems have been fixed in version 1.8.2.dfsg-4. We recommend that you upgrade your moodle package.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-5153
CVE-2009-0500
CVE-2009-0502
DSA-1724-1
Platform(s):Debian GNU/Linux 4.0
Product(s):moodle
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Installed architecture is all
  • AND moodle DPKG is earlier than 1.6.3-2+etch2
  • BACK