First published: Wed Dec 07 2011(Updated: )
A number of flaws have been fixed in new upstream Moodle 2.1.3 [1], 2.0.6 [2], and 1.9.15 [3] releases. These do not have CVEs assigned (request pending), and since Fedora/EPEL will rebase to the latest versions of each branch, I'm summarizing them all here rather than creating a number of separate bugs. [1] <a href="http://docs.moodle.org/dev/Moodle_2.1.3_release_notes">http://docs.moodle.org/dev/Moodle_2.1.3_release_notes</a> [2] <a href="http://docs.moodle.org/dev/Moodle_2.0.6_release_notes">http://docs.moodle.org/dev/Moodle_2.0.6_release_notes</a> [3] <a href="http://docs.moodle.org/dev/Moodle_1.9.15_release_notes">http://docs.moodle.org/dev/Moodle_1.9.15_release_notes</a> MSA-11-0042: Information leak in Wiki Affects: 2.1.x, 2.0.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git;a=commit;h=140af2a0f0a4598bf568b9ae182cb81eb583edeb">http://git.moodle.org/gw?p=moodle.git;a=commit;h=140af2a0f0a4598bf568b9ae182cb81eb583edeb</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191747">http://moodle.org/mod/forum/discuss.php?d=191747</a> MSA-11-0043: Possible link redirect in Calendar Affects: 2.1.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28720&sr=1">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28720&sr=1</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191748">http://moodle.org/mod/forum/discuss.php?d=191748</a> MSA-11-0044: Expired identification information shown in Web services Affects: 2.1.x, 2.0.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28670&sr=1">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28670&sr=1</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191750">http://moodle.org/mod/forum/discuss.php?d=191750</a> MSA-11-0045: Potential to masquerade through MNet Affects: 2.1.x, 2.0.x, 1.9.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=10df8657c1c138c0d0ab1d4796c552fcec0c299b">http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=10df8657c1c138c0d0ab1d4796c552fcec0c299b</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191751">http://moodle.org/mod/forum/discuss.php?d=191751</a> MSA-11-0046: Insecure authentication transmission Affects: 1.9.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=01dd64a8c8aa95f793accea371b2392e662663c5">http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=01dd64a8c8aa95f793accea371b2392e662663c5</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191752">http://moodle.org/mod/forum/discuss.php?d=191752</a> MSA-11-0047: Possible injection attack in Calendar Affects: 2.1.x, 2.0.x, 1.9.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=581e8dba387f090d89382115fd850d8b44351526">http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=581e8dba387f090d89382115fd850d8b44351526</a> Reference: moodle.org/mod/forum/discuss.php?d=191754 MSA-11-0048: Password loss issue Affects: 2.1.x, 2.0.x, 1.9.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=e079e82c087becf06d902089d14f3f76686bde19">http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=e079e82c087becf06d902089d14f3f76686bde19</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191755">http://moodle.org/mod/forum/discuss.php?d=191755</a> MSA-11-0049: Network restriction ineffective with MNet Affects: 1.9.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=3ab2851d2a59721445945d0706c58092e07e861e">http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=3ab2851d2a59721445945d0706c58092e07e861e</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191756">http://moodle.org/mod/forum/discuss.php?d=191756</a> MSA-11-0050: Backup capability issue Affects: 2.1.x, 2.0.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-29591">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-29591</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191758">http://moodle.org/mod/forum/discuss.php?d=191758</a> MSA-11-0051: Authentication issue with Web services Affects: 2.1.x, 2.0.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28629">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28629</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191759">http://moodle.org/mod/forum/discuss.php?d=191759</a> MSA-11-0052: Potential to exploit developer debugging scripts Affects: 2.1.x, 2.0.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git;a=commit;h=187672608ec96659e07f2461b3b83634debd16cb">http://git.moodle.org/gw?p=moodle.git;a=commit;h=187672608ec96659e07f2461b3b83634debd16cb</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191760">http://moodle.org/mod/forum/discuss.php?d=191760</a> MSA-11-0053: Security and system administration conflict Affects: 2.1.x, 2.0.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git;a=commit;h=ade30ad3c420ce035a3d68287db701b70e806b3f">http://git.moodle.org/gw?p=moodle.git;a=commit;h=ade30ad3c420ce035a3d68287db701b70e806b3f</a> Refrence: <a href="http://moodle.org/mod/forum/discuss.php?d=191761">http://moodle.org/mod/forum/discuss.php?d=191761</a> MSA-11-0054: Personal information leak Affects: 2.1.x, 2.0.x Fix: <a href="http://git.moodle.org/gw?p=moodle.git;a=commit;h=e94113a859015a4a80b9397957b8fc4044e2951f">http://git.moodle.org/gw?p=moodle.git;a=commit;h=e94113a859015a4a80b9397957b8fc4044e2951f</a> Reference: <a href="http://moodle.org/mod/forum/discuss.php?d=191762">http://moodle.org/mod/forum/discuss.php?d=191762</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | =2.0.2 | |
Moodle Moodle | =2.0.1 | |
Moodle Moodle | =2.0.4 | |
Moodle Moodle | =2.0.3 | |
Moodle Moodle | =2.0.5 | |
Moodle Moodle | =2.0.0 | |
Moodle Moodle | =2.1.2 | |
Moodle Moodle | =2.1.1 | |
Moodle Moodle | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.