![]() |
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.
|
|
google unix.com
|
|||||||
| Forums | Register | Forum Rules | Links | Albums | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| Security Advisories (RSS) UNIX and Linux Security Advisories Via RSS News |
More UNIX and Linux Forum Topics You Might Find Helpful
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Debian: New moodle packages fix several vulnerabilities | iBot | Security Advisories (RSS) | 0 | 12-22-2008 11:20 AM |
| BitNami Moodle Stack 1.9.3-0 (Module branch) | iBot | Software Releases - RSS News | 0 | 12-16-2008 07:10 PM |
| BitNami Moodle Stack 1.9.2-1 (Default branch) | iBot | Software Releases - RSS News | 0 | 11-05-2008 11:10 PM |
| USN-658-1: Moodle vulnerability | iBot | Security Advisories (RSS) | 0 | 10-23-2008 05:40 PM |
| JumpBox for Moodle Course Management System 1.1.2 (Default branch) | iBot | Software Releases - RSS News | 0 | 08-15-2008 02:50 AM |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
|||||
|
USN-791-2: Moodle vulnerability
Referenced CVEs:
CVE-2009-1171 Description: =========================================================== Ubuntu Security Notice USN-791-2 June 24, 2009 moodle vulnerability CVE-2009-1171 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 9.04: moodle 1.9.4.dfsg-0ubuntu1.1 After a standard system upgrade you need to access the Moodle instance and accept the database update to clear any invalid cached data. Details follow: Christian Eibl discovered that the TeX filter in Moodle allowed any function to be used. An authenticated remote attacker could post a specially crafted TeX formula to execute arbitrary TeX functions, potentially reading any file accessible to the web server user, leading to a loss of privacy. (CVE-2009-1171, MSA-09-0009) More... |
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|