<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Security Announcements</title>
    <link>http://moodle.org/mod/forum/view.php?f=996</link>
    <description>
&lt;div style=&quot;text-align:left;&quot;&gt; &lt;span class=&quot;nolink&quot;&gt;
  &lt;h2&gt;Moodle Security Procedures&lt;/h2&gt;
  &lt;p&gt;We treat security issues in Moodle software very seriously. Even though we dedicate a lot of time designing our code to avoid such problems, it is inevitable in a project of this size that new vulnerabilities will occasionally be discovered.&lt;/p&gt;
  &lt;p&gt;We practice responsible disclosure, which means we have a policy of disclosing all security issues that come to our attention, but only after we have solved the issue and given registered Moodle sites some time to upgrade or patch their installations.&lt;/p&gt;
  &lt;p&gt;We welcome reports of security issues and will work with reporters to fix problems and publicise patches to Moodle users as quickly as possible.&lt;/p&gt; &lt;br /&gt;
  &lt;h3&gt;How can I report a security issue?&lt;/h3&gt;
  &lt;p&gt;Please &amp;quot;Create a new issue&amp;quot; in the Moodle Tracker describing the problem (and solution if possible) in detail. Make sure you set the &lt;strong&gt;Security Level&lt;/strong&gt; accurately to make sure that the security team sees it. Bugs classified as a &amp;quot;Serious security issue&amp;quot; will be hidden from the general public until the security team (led by Petr Skoda) is able to resolve it and publish fixes to registered Moodle sites (see below).&lt;/p&gt; &lt;br /&gt;
  &lt;h3&gt;How can I keep my site secure?&lt;/h3&gt;
  &lt;ol&gt;
    &lt;li&gt;The usual way is to update your whole Moodle to the latest stable release of the version you are using. It is very safe to go from 1.8.1 to 1.8.2+, for example, at any time. CVS is a very easy way to do this.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
    &lt;li&gt;Many of the notices will include patch information. If you are fairly confident with editing scripts, then it may be easier for you to just patch the affected file.&lt;/li&gt;
  &lt;/ol&gt; &lt;br /&gt;
  &lt;h3&gt;How can I keep track of recent security issues?&lt;/h3&gt;
  &lt;ol&gt;
    &lt;li&gt;Register your Moodle sites with moodle.org (visit admin/index.php in your installation to see the registration button), making sure to enable the option of being notified about security issues and updates. After your registration is accepted, your email address will be automatically added to our low-volume securityalerts mailing list.&lt;/li&gt;
    &lt;li&gt;Eventually, all important security issues are published to the general public via the forum on this page. You can subscribe to the RSS feed on this page to automatically add new issues in your favourite feed reader or portal. (Please note that security alerts prior to 2008 were made on a different site and do not appear here.)&lt;/li&gt;
  &lt;/ol&gt; &lt;br /&gt;
  &lt;h3&gt;See also&lt;/h3&gt;
  &lt;ul&gt;
    &lt;li&gt;Security documentation&lt;/li&gt;
    &lt;li&gt;Security FAQ&lt;/li&gt;
  &lt;/ul&gt; &lt;/span&gt; &lt;/div&gt;</description>
    <generator>Moodle</generator>
    <copyright>&amp;#169; 2009 Moodle.org</copyright>
    <image>
      <url>http://moodle.org/pix/i/rsssitelogo.gif</url>
      <title>moodle</title>
      <link>http://moodle.org</link>
      <width>140</width>
      <height>35</height>
    </image>
    <item>
      <category>MSA-09-0031: SQL injection in SCORM module</category>
      <title>MSA-09-0031: SQL injection in SCORM module</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139120&amp;parent=606931</link>
      <pubDate>Tue, 01 Dec 2009 21:01:31 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Topic: 
    &lt;/td&gt; 
    &lt;td&gt;SQL injection in SCORM module 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Severity/Risk: 
    &lt;/td&gt; 
    &lt;td&gt;Minor 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Versions affected: 
    &lt;/td&gt; 
    &lt;td&gt; &amp;lt;1.8.11 and &amp;lt;1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Reported by: 
    &lt;/td&gt; 
    &lt;td&gt;Andrea Tuccia 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Issue no.: 
    &lt;/td&gt; 
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20955&quot;&gt;MDL-20955&lt;/a&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Solution: 
    &lt;/td&gt; 
    &lt;td&gt; upgrade to 1.8.11 or 1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Workaround: 
    &lt;/td&gt; 
    &lt;td&gt;none&lt;br /&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;br /&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Andrea Tuccia discovered escaping issue when processing AICC CRS file (Course_Title). The problem is marked as minor because only trusted users are allow to upload SCORM packages.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139120&amp;parent=606931</guid>
    </item>
    <item>
      <category>MSA-09-0030: New detection of insecure flash player plugins</category>
      <title>MSA-09-0030: New detection of insecure flash player plugins</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139119&amp;parent=606930</link>
      <pubDate>Tue, 01 Dec 2009 20:58:30 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;New detection of insecure flash player plugins
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.9.7
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;internal code review
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20841&quot;&gt;MDL-20841&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to 1.9.7
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;none&lt;br /&gt;
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Older Flash versions that do not respect the download http header may be used to gain unauthorised access. Moodle is now able to detect obsolete and vulnerable Flash plugin versions. Moodle will actually refuse to send uploaded files to older Flash plugins and will instead send an alternative Flash file that asks users to upgrade. All administrators and teachers should upgrade their computers as soon as possible.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139119&amp;parent=606930</guid>
    </item>
    <item>
      <category>MSA-09-0029: Multiple password related issues</category>
      <title>MSA-09-0029: Multiple password related issues</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139111&amp;parent=606897</link>
      <pubDate>Tue, 01 Dec 2009 19:44:14 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Topic: 
    &lt;/td&gt; 
    &lt;td&gt;Multiple password related issues&lt;br /&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Severity/Risk: 
    &lt;/td&gt; 
    &lt;td&gt;Critical&lt;br /&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Versions affected: 
    &lt;/td&gt; 
    &lt;td&gt; &amp;lt;1.8.11 and &amp;lt;1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Reported by: 
    &lt;/td&gt; 
    &lt;td&gt;exploit of weak passwords published anonymously on moodle.org and multiple other reports 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Issue no.: 
    &lt;/td&gt; 
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-18807&quot;&gt;MDL-18807&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-18006&quot;&gt;MDL-18006&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-19608&quot;&gt;MDL-19608&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20934&quot;&gt;MDL-20934&lt;/a&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Solution: 
    &lt;/td&gt; 
    &lt;td&gt; upgrade to 1.8.11 or 1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Workaround: 
    &lt;/td&gt; 
    &lt;td&gt;set up password salt in config.php, enforce strong password policy, force password change on important accounts, verify LDAP configuration if used 
    &lt;/td&gt; 
  &lt;/tr&gt; &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;br /&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Administrators are now forced to change their password after upgrading. The installer now puts a random password salt into config.php, existing sites notify administrators to configure the salt via security overview reports. Strong password policy is now enabled by default. Only internal authentication plugins now store password hashes in user table, cached hashes are removed for all external plugins (though the LDAP plugin already had the option to prevent passwords in user table). Bulk user actions now contain an option to force password change.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139111&amp;parent=606897</guid>
    </item>
    <item>
      <category>MSA-09-0028: Multiple backup/restore related issues </category>
      <title>MSA-09-0028: Multiple backup/restore related issues </title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139110&amp;parent=606894</link>
      <pubDate>Tue, 01 Dec 2009 19:39:36 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Topic: 
    &lt;/td&gt; 
    &lt;td&gt;Multiple backup/restore related issues 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Severity/Risk: 
    &lt;/td&gt; 
    &lt;td&gt;Critical&lt;br /&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Versions affected: 
    &lt;/td&gt; 
    &lt;td&gt; &amp;lt;1.8.11 and &amp;lt;1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Reported by: 
    &lt;/td&gt; 
    &lt;td&gt;multiple reports 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Issue no.: 
    &lt;/td&gt; 
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20838&quot;&gt;MDL-20838&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20849&quot;&gt;MDL-20849&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20939&quot;&gt;MDL-20939&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20932&quot;&gt;MDL-20932&lt;/a&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Solution: 
    &lt;/td&gt; 
    &lt;td&gt; upgrade to 1.8.11 or 1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Workaround: 
    &lt;/td&gt; 
    &lt;td&gt;remove backup capability from all users 
    &lt;/td&gt; 
  &lt;/tr&gt; &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;br /&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;User password hashes and secrets are now never included in backup files. There are also new capabilities that control backup/restore of all user information (separately from the course data), and these are off by default. The admin has much better control over who has these capabilities, and the security overview report now gives a comprehensive picture of dangerous roles, overrides, users etc. Even if this capability is enabled, only enrolled users can be included in backup files. &lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139110&amp;parent=606894</guid>
    </item>
    <item>
      <category>MSA-09-0027: Login information can be sent unsecured even when site is configured to use SSL for logins</category>
      <title>MSA-09-0027: Login information can be sent unsecured even when site is configured to use SSL for logins</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139107&amp;parent=606889</link>
      <pubDate>Tue, 01 Dec 2009 19:32:08 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Topic: 
    &lt;/td&gt; 
    &lt;td&gt;Login information can be sent unsecured when site is configured to use SSL for logins 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Severity/Risk: 
    &lt;/td&gt; 
    &lt;td&gt;Minor 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Versions affected: 
    &lt;/td&gt; 
    &lt;td&gt; &amp;lt;1.8.11 and &amp;lt;1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Reported by: 
    &lt;/td&gt; 
    &lt;td&gt;Mike Churchward 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Issue no.: 
    &lt;/td&gt; 
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20958&quot;&gt;MDL-20958&lt;/a&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Solution: 
    &lt;/td&gt; 
    &lt;td&gt; upgrade to 1.8.11 or 1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Workaround: 
    &lt;/td&gt; 
    &lt;td&gt;apply patch&lt;br /&gt;&lt;a href=&quot;http://cvs.moodle.org/moodle/login/index_form.html?r1=1.50.2.1&amp;r2=1.50.2.2&quot;&gt;http://cvs.moodle.org/moodle/login/index_form.html?r1=1.50.2.1&amp;amp;r2=1.50.2.2 &lt;/a&gt;&lt;br /&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;br /&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Mike Churchward described a potential problem and proposed a solution that prevents sending of password via unsecured connection when SSL required only for logins.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139107&amp;parent=606889</guid>
    </item>
    <item>
      <category>MSA-09-0026: Invalid application access control in MNET interface</category>
      <title>MSA-09-0026: Invalid application access control in MNET interface</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139106&amp;parent=606887</link>
      <pubDate>Tue, 01 Dec 2009 19:27:06 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Invalid application access control in MNET interface
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.8.11 and &amp;lt;1.9.7
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Adrian Schlegel
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20639&quot;&gt;MDL-20639&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to 1.8.11 or 1.9.7
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;apply patch&lt;br /&gt;&lt;a href=&quot;http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.16.2.10&amp;r2=1.16.2.11&quot;&gt;http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.16.2.10&amp;amp;r2=1.16.2.11&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.9.2.7&amp;r2=1.9.2.8&quot;&gt;http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.9.2.7&amp;amp;r2=1.9.2.8 &lt;/a&gt;&lt;br /&gt;
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Adrian Schlegel reported a serious problem in the MNET implementation allowing execution of any MNET function from all registered remote servers. The server is vulnerable only when MNET services are enabled on the server.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139106&amp;parent=606887</guid>
    </item>
    <item>
      <category>MSA-09-0025: Unneeded MD5 hashes removed from user table</category>
      <title>MSA-09-0025: Unneeded MD5 hashes removed from user table</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139105&amp;parent=606883</link>
      <pubDate>Tue, 01 Dec 2009 19:22:46 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Unneeded MD5 hashes removed from user table
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.8.11 and &amp;lt;1.9.7
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;internal code review
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20934&quot;&gt;MDL-20934&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to 1.8.11 or 1.9.7
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;none
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;All authentication plugins except LDAP were storing md5 hashes of passwords in the user table, but these &amp;quot;cached&amp;quot; hashes were only actually used in some authentication plugins. We have now replaced md5 hashes with 'not cached' flag in all external authentication types. Please note this change may break backwards compatibility and some 3rd party modifications. If you have any custom code using this field in the table it will need to be rewritten.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139105&amp;parent=606883</guid>
    </item>
    <item>
      <category>MSA-09-0024: Insufficient access control in glossary</category>
      <title>MSA-09-0024: Insufficient access control in glossary</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139103&amp;parent=606881</link>
      <pubDate>Tue, 01 Dec 2009 19:18:44 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Topic: 
    &lt;/td&gt; 
    &lt;td&gt;Insufficient access control in glossary 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Severity/Risk: 
    &lt;/td&gt; 
    &lt;td&gt;Major 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Versions affected: 
    &lt;/td&gt; 
    &lt;td&gt; &amp;lt;1.8.11 and &amp;lt;1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Reported by: 
    &lt;/td&gt; 
    &lt;td&gt;internal code review 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Issue no.: 
    &lt;/td&gt; 
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20928&quot;&gt;MDL-20928&lt;/a&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Solution: 
    &lt;/td&gt; 
    &lt;td&gt; upgrade to 1.8.11 or 1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Workaround: 
    &lt;/td&gt; 
    &lt;td&gt;use new mod/glossary/showentry.php 
    &lt;/td&gt; 
  &lt;/tr&gt; &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;We have discovered that insufficient access control may allow unauthorised users to view glossary entries.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139103&amp;parent=606881</guid>
    </item>
    <item>
      <category>MSA-09-0023: User account disclosure in LAMS module</category>
      <title>MSA-09-0023: User account disclosure in LAMS module</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139102&amp;parent=606880</link>
      <pubDate>Tue, 01 Dec 2009 19:15:42 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Topic: 
    &lt;/td&gt; 
    &lt;td&gt;User account disclosure in LAMS module 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Severity/Risk: 
    &lt;/td&gt; 
    &lt;td&gt;Major 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Versions affected: 
    &lt;/td&gt; 
    &lt;td&gt; &amp;lt;1.8.11 and &amp;lt;1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Reported by: 
    &lt;/td&gt; 
    &lt;td&gt;internal code review 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Issue no.: 
    &lt;/td&gt; 
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20924&quot;&gt;MDL-20924&lt;/a&gt; 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Solution: 
    &lt;/td&gt; 
    &lt;td&gt; upgrade to 1.8.11 or 1.9.7 
    &lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
    &lt;td&gt;Workaround: 
    &lt;/td&gt; 
    &lt;td&gt;uninstall module and delete mod/lams directory 
    &lt;/td&gt; 
  &lt;/tr&gt; &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;LAMS module code discloses username, firstname and lastname database fields from user table. This information could be used in other types of attacks.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139102&amp;parent=606880</guid>
    </item>
    <item>
      <category>MSA-09-0022: Multiple CSRF problems fixed</category>
      <title>MSA-09-0022: Multiple CSRF problems fixed</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=139100&amp;parent=606874</link>
      <pubDate>Tue, 01 Dec 2009 19:11:50 GMT</pubDate>
      <dc:creator>Helen Foster</dc:creator>
      <description>by Helen Foster. &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Multiple CSRF problems fixed
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.8.11 and &amp;lt;1.9.7
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;internal code review
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20705&quot;&gt;MDL-20705&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20707&quot;&gt;MDL-20707&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20706&quot;&gt;MDL-20706&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20925&quot;&gt;MDL-20925&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20929&quot;&gt;MDL-20929&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20930&quot;&gt;MDL-20930&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20931&quot;&gt;MDL-20931&lt;/a&gt;, &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20901&quot;&gt;MDL-20901&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to 1.8.11 or 1.9.7
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;none
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;We have discovered and fixed multiple cross site request forgery (CSRF) problems during internal code review. &lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=139100&amp;parent=606874</guid>
    </item>
  </channel>
</rss>