News

Friday, October 24, 2008

ubuntu-security-announce Digest, Vol 49, Issue 9

Send ubuntu-security-announce mailing list submissions to
ubuntu-security-announce@lists.ubuntu.com

To subscribe or unsubscribe via the World Wide Web, visit
https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
or, via email, send a message with subject or body 'help' to
ubuntu-security-announce-request@lists.ubuntu.com

You can reach the person managing the list at
ubuntu-security-announce-owner@lists.ubuntu.com

When replying, please edit your Subject line so it is more specific
than "Re: Contents of ubuntu-security-announce digest..."


Today's Topics:

1. [USN-658-1] Moodle vulnerability (Kees Cook)


----------------------------------------------------------------------

Message: 1
Date: Thu, 23 Oct 2008 14:44:06 -0700
From: Kees Cook <kees@ubuntu.com>
Subject: [USN-658-1] Moodle vulnerability
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <20081023214406.GF21108@outflux.net>
Content-Type: text/plain; charset="us-ascii"

===========================================================
Ubuntu Security Notice USN-658-1 October 23, 2008
moodle vulnerability
CVE-2008-1502
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 7.10
Ubuntu 8.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 7.10:
moodle 1.8.2-1ubuntu2.1

Ubuntu 8.04 LTS:
moodle 1.8.2-1ubuntu4.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

Lukasz Pilorz discovered that the HTML filtering used in Moodle was not
strict enough. A remote attacker could send malicious requests to Moodle
and execute arbitrary code as the web server user.


Updated packages for Ubuntu 7.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu2.1.diff.gz
Size/MD5: 19705 cddd2761b29fe98f6f0686155b299f48
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu2.1.dsc
Size/MD5: 741 1590c124a2dbff31fa8aee6f5a3add91
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2.orig.tar.gz
Size/MD5: 10157112 4e6afcfd567571af0638533d157f9181

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu2.1_all.deb
Size/MD5: 9294484 c7ec1ead92a220103ea5ca5b439718bb

Updated packages for Ubuntu 8.04 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu4.1.diff.gz
Size/MD5: 19903 31e6f4b817f844d93c4704cdfa70caf0
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu4.1.dsc
Size/MD5: 741 7968ef24932d8eae67263dc57985050c
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2.orig.tar.gz
Size/MD5: 10157112 4e6afcfd567571af0638533d157f9181

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubuntu4.1_all.deb
Size/MD5: 9294736 536da637d3f4f399a467a077575660e4
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 235 bytes
Desc: Digital signature
Url : https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20081023/fea06170/attachment-0001.pgp

------------------------------

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce


End of ubuntu-security-announce Digest, Vol 49, Issue 9
*******************************************************

No comments:

Blog Archive