U radu programskog paketa moodle otkriveno je više sigurnosnih propusta. Napadači mogu navedene ranjivosti iskoristiti za neovlašteni pristup sustavu, otkrivanje osjetljivih informacija i umetanje proizvoljnih podataka.
U radu programskog paketa primjećeno je nekoliko nedostataka povezanih s neodgovarajućim rukovanjem "recaptcha" slikama, nepravilnim postavkama varijable "config", korištenjem fiksnih ključeva za kriptiranje i dekriptiranje kolačića (eng. cookies), neodgovarajućom provjerom postavki elektroničke pošte te sa ubacivanjem zaglavlja u adrese elektroničke pošte, korištenjem tokena za pristup sustavu, otkrivanjem lozinke i neodgovarajućom provjerom ponavljajućih elemenata.
Posljedica:
Zlonamjerni napadači mogu iskoristiti navedene nepravilnosti za neovlašteni pristup sustavu, pregled osjetljivih podataka i umetanje proizvoljnih podataka.
Rješenje:
Korisnicima se savjetuje korištenje nadogradnje koja otklanja opisane nedostatke.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-0913
2012-01-25 21:58:11
--------------------------------------------------------------------------------
Name : moodle
Product : Fedora 16
Version : 2.0.7
Release : 1.fc16
URL : http://moodle.org/
Summary : A Course Management System
Description :
Moodle is a course management system (CMS) - a free, Open Source software
package designed using sound pedagogical principles, to help educators create
effective online learning communities.
--------------------------------------------------------------------------------
Update Information:
CVE-2012-0792 CVE-2012-0793 CVE-2012-0794 CVE-2012-0795 CVE-2012-0796
CVE-2012-0797 CVE-2012-0798 CVE-2012-0799 CVE-2012-0800 CVE-2012-0801
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jan 24 2012 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 2.0.7-1
- New upstream, BZ 783534.
* Fri Dec 9 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 2.0.6-1
- New upstream, BZ 761249.
* Fri Oct 21 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 2.0.5-1
- New upstream, BZ 747445.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #783532 - moodle: multiple security fixes in 2.2.1, 2.1.4, 2.0.7,
1.9.16
https://bugzilla.redhat.com/show_bug.cgi?id=783532
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update moodle' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-0939
2012-01-25 21:59:46
--------------------------------------------------------------------------------
Name : moodle
Product : Fedora 15
Version : 1.9.16
Release : 1.fc15
URL : http://moodle.org/
Summary : A Course Management System
Description :
Moodle is a course management system (CMS) - a free, Open Source software
package designed using sound pedagogical principles, to help educators create
effective online learning communities.
--------------------------------------------------------------------------------
Update Information:
CVE-2012-0792 CVE-2012-0793 CVE-2012-0794 CVE-2012-0795 CVE-2012-0796
CVE-2012-0797 CVE-2012-0798 CVE-2012-0799 CVE-2012-0800 CVE-2012-0801
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jan 24 2012 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.9.16-1
- New upstream, security fixes, 783534.
* Fri Dec 9 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.9.15-1
- New upstream, security fixes, 761249.
* Fri Oct 21 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.9.14-1
- New upstream, security fixes, 747445.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #783532 - moodle: multiple security fixes in 2.2.1, 2.1.4, 2.0.7,
1.9.16
https://bugzilla.redhat.com/show_bug.cgi?id=783532
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update moodle' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke