First published: Tue Dec 08 2020(Updated: )
A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | >=3.5.0<3.5.14 | |
Moodle Moodle | >=3.7.0<3.7.8 | |
Moodle Moodle | >=3.8.0<3.8.5 | |
Moodle Moodle | >=3.9.0<3.9.2 | |
composer/moodle/moodle | >=3.5<3.5.14 | 3.5.14 |
composer/moodle/moodle | >=3.7<3.7.8 | 3.7.8 |
composer/moodle/moodle | >=3.8<3.8.5 | 3.8.5 |
composer/moodle/moodle | >=3.9<3.9.2 | 3.9.2 |
>=3.5.0<3.5.14 | ||
>=3.7.0<3.7.8 | ||
>=3.8.0<3.8.5 | ||
>=3.9.0<3.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25630 is a vulnerability in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, leading to a denial of service risk.
Versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13, and earlier unsupported versions of Moodle are affected by CVE-2020-25630.
CVE-2020-25630 has a severity keyword of 'high' and a severity value of 7.5.
CVE-2020-25630 can lead to a denial of service risk in Moodle.
To fix CVE-2020-25630, update to a version of Moodle that is not affected by the vulnerability.