<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Security Announcements</title>
    <link>http://moodle.org/mod/forum/view.php?f=996</link>
    <description>
&lt;div style=&quot;text-align:left;&quot;&gt; &lt;span class=&quot;nolink&quot;&gt;
  &lt;h2&gt;Moodle Security Procedures&lt;/h2&gt;
  &lt;p&gt;We treat security issues in Moodle software very seriously. Even though we dedicate a lot of time designing our code to avoid such problems, it is inevitable in a project of this size that new vulnerabilities will occasionally be discovered.&lt;/p&gt;
  &lt;p&gt;We practice responsible disclosure, which means we have a policy of disclosing all security issues that come to our attention, but only after we have solved the issue and given registered Moodle sites some time to upgrade or patch their installations.&lt;/p&gt;
  &lt;p&gt;We welcome reports of security issues and will work with reporters to fix problems and publicise patches to Moodle users as quickly as possible.&lt;/p&gt; &lt;br /&gt;
  &lt;h3&gt;How can I report a security issue?&lt;/h3&gt;
  &lt;p&gt;Please &amp;quot;Create a new issue&amp;quot; in the Moodle Tracker describing the problem (and solution if possible) in detail. Make sure you set the &lt;strong&gt;Security Level&lt;/strong&gt; accurately to make sure that the security team sees it. Bugs classified as a &amp;quot;Serious security issue&amp;quot; will be hidden from the general public until the security team (led by Petr Skoda) is able to resolve it and publish fixes to registered Moodle sites (see below).&lt;/p&gt; &lt;br /&gt;
  &lt;h3&gt;How can I keep my site secure?&lt;/h3&gt;
  &lt;ol&gt;
    &lt;li&gt;The usual way is to update your whole Moodle to the latest stable release of the version you are using. It is very safe to go from 1.8.1 to 1.8.2+, for example, at any time. CVS is a very easy way to do this.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
    &lt;li&gt;Many of the notices will include patch information. If you are fairly confident with editing scripts, then it may be easier for you to just patch the affected file.&lt;/li&gt;
  &lt;/ol&gt; &lt;br /&gt;
  &lt;h3&gt;How can I keep track of recent security issues?&lt;/h3&gt;
  &lt;ol&gt;
    &lt;li&gt;Register your Moodle sites with moodle.org (visit admin/index.php in your installation to see the registration button), making sure to enable the option of being notified about security issues and updates. After your registration is accepted, your email address will be automatically added to our low-volume securityalerts mailing list.&lt;/li&gt;
    &lt;li&gt;Eventually, all important security issues are published to the general public via the forum on this page. You can subscribe to the RSS feed on this page to automatically add new issues in your favourite feed reader or portal. (Please note that security alerts prior to 2008 were made on a different site and do not appear here.)&lt;/li&gt;
  &lt;/ol&gt; &lt;br /&gt;
  &lt;h3&gt;See also&lt;/h3&gt;
  &lt;ul&gt;
    &lt;li&gt;Security documentation&lt;/li&gt;
    &lt;li&gt;Security FAQ&lt;/li&gt;
  &lt;/ul&gt; &lt;/span&gt; &lt;/div&gt;</description>
    <generator>Moodle</generator>
    <copyright>&amp;#169; 2009 Moodle.org</copyright>
    <image>
      <url>http://moodle.org/pix/i/rsssitelogo.gif</url>
      <title>moodle</title>
      <link>http://moodle.org</link>
      <width>140</width>
      <height>35</height>
    </image>
    <item>
      <category>MSA-09-0021: Error in ADODB OCI8/MSSQL drivers allows SQL injection vulnerability</category>
      <title>MSA-09-0021: Error in ADODB OCI8/MSSQL drivers allows SQL injection vulnerability</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=136886&amp;parent=597608</link>
      <pubDate>Mon, 02 Nov 2009 20:09:00 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Error in ADODB OCI8/MSSQL drivers allows SQL injection vulnerability
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Critical (only servers using Oracle and MS SQL databases)
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.9.6
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Sam Moffatt
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-19452&quot;&gt;MDL-19452&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to latest weekly build or 1.9.6
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;none
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Sam Moffatt discovered a potential problem in the way ADODB library is quoting special characters when the database engine is using Sybase style quoting.&lt;/p&gt; &lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=136886&amp;parent=597608</guid>
    </item>
    <item>
      <category>MSA-09-0020: Teachers can view students' grades in all courses in the overview report</category>
      <title>MSA-09-0020: Teachers can view students' grades in all courses in the overview report</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=136884&amp;parent=597604</link>
      <pubDate>Mon, 02 Nov 2009 19:52:58 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Teachers can view students' grades in all courses in the overview report
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Minor
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.9.6
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Ratana Lim
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20355&quot;&gt;MDL-20355&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to latest weekly build or 1.9.6
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;remove the overview report link - see http://docs.moodle.org/en/Simplifying_the_gradebook
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Teachers could view students' grades in all courses, including courses for which they do not have teacher rights, in the overview report.&lt;/p&gt; &lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=136884&amp;parent=597604</guid>
    </item>
    <item>
      <category>MSA-09-0019: SQL injection in update_record</category>
      <title>MSA-09-0019: SQL injection in update_record</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=136882&amp;parent=597602</link>
      <pubDate>Mon, 02 Nov 2009 19:49:21 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;SQL injection in update_record
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Critical
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.9.6, &amp;lt;1.8.10, 1.7.x
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Georg-Christian Pranschke
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20309&quot;&gt;MDL-20309&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to latest weekly builds, 1.9.6 or 1.8.10
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;apply patches:&lt;br /&gt;
      &lt;ul&gt;
        &lt;li&gt;&lt;font size=&quot;2&quot;&gt;http://cvs.moodle.org/moodle/lib/dmllib.php?r1=1.116.2.32&amp;amp;r2=1.116.2.33 &lt;br /&gt;&lt;/font&gt;&lt;/li&gt;
        &lt;li&gt;&lt;font size=&quot;2&quot;&gt;http://cvs.moodle.org/moodle/lib/dmllib.php?r1=1.91.2.23&amp;amp;r2=1.91.2.24 &lt;/font&gt;&lt;/li&gt;
      &lt;/ul&gt;
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Georg-Christian Pranschke discovered a serious problem in update_record function. This problem may allow any registered user to exploit several different scripts.&lt;/p&gt; &lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=136882&amp;parent=597602</guid>
    </item>
    <item>
      <category>MSA-09-0018: Incorrect escaping when updating first post in a single simple discussion forum type</category>
      <title>MSA-09-0018: Incorrect escaping when updating first post in a single simple discussion forum type</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=136881&amp;parent=597599</link>
      <pubDate>Mon, 02 Nov 2009 19:46:04 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Incorrect escaping when updating first post in a single simple discussion forum type
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Minor
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.9.6, &amp;lt;1.8.10
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Nicola Vitacolonna
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20555&quot;&gt;MDL-20555&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to latest weekly build or 1.9.6
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;none
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Nicola Vitacolonna discovered forum introduction is incorrectly escaped when editing the first post of a single simple discussion forum. This can potentially lead to SQL injection attacks by teachers. Students can not exploit this problem.&lt;/p&gt; &lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=136881&amp;parent=597599</guid>
    </item>
    <item>
      <category>MSA-09-0017: Upgrade code in 1.9 does not escape tags properly</category>
      <title>MSA-09-0017: Upgrade code in 1.9 does not escape tags properly</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=136880&amp;parent=597597</link>
      <pubDate>Mon, 02 Nov 2009 19:43:46 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Upgrade code 1.9 does not escape tags properly
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Minor
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.9.6
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Matt Oquist
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-19709&quot;&gt;MDL-19709&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; do not use 1.9.0-1.9.5 when upgrading from any previous version
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;The upgrade code does not properly escape tags properly when upgrading from any version before 1.9.0.&lt;/p&gt; &lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=136880&amp;parent=597597</guid>
    </item>
    <item>
      <category>MSA-09-0016: Email not properly escaped on user edit page</category>
      <title>MSA-09-0016: Email not properly escaped on user edit page</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=136879&amp;parent=597596</link>
      <pubDate>Mon, 02 Nov 2009 19:41:06 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Email not properly escaped on user edit page
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Minor
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt;1.9.6
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;Alan Trick
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20295&quot;&gt;MDL-20295&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to latest weekly build or 1.9.6
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;disable email change confirmation (not recommended)
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;Alan Trick discovered that the email change confirmation code does not escape the email addresses properly. This problem is marked as minor because the email address is validated and can not contain an arbitrary text.&lt;/p&gt; &lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=136879&amp;parent=597596</guid>
    </item>
    <item>
      <category>MSA-09-0015: Customised PhpMyAdmin upgraded to 2.11.9.6</category>
      <title>MSA-09-0015: Customised PhpMyAdmin upgraded to 2.11.9.6</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=135222&amp;parent=590822</link>
      <pubDate>Wed, 14 Oct 2009 18:12:59 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Topic:&lt;br /&gt;
    &lt;/td&gt;&lt;td&gt;Customised PhpMyAdmin upgraded to 2.11.9.6&lt;br /&gt;
    &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Severity:&lt;br /&gt;
    &lt;/td&gt;&lt;td&gt;Major&lt;br /&gt;
    &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Versions affected:&lt;br /&gt;
    &lt;/td&gt;&lt;td&gt; all&lt;br /&gt;
    &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Reported by:&lt;br /&gt;
    &lt;/td&gt;&lt;td&gt;upstream - PMASA-2009-6; CVE-2009-3696  and  CVE-2009-3697&lt;br /&gt;
    &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Issue no.:&lt;br /&gt;
    &lt;/td&gt;&lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-20553&quot;&gt;MDL-20553&lt;/a&gt;&lt;br /&gt;
    &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Solution:&lt;br /&gt;
    &lt;/td&gt;&lt;td&gt; Install latest package from &lt;a href=&quot;http://moodle.org/mod/data/view.php?d=13&amp;rid=448&quot;&gt;http://moodle.org/mod/data/view.php?d=13&amp;amp;rid=448&lt;/a&gt; or cvs&lt;br /&gt;
    &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Workaround:&lt;br /&gt;
    &lt;/td&gt;&lt;td&gt;delete admin/mysql/*&lt;br /&gt;
    &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;&lt;a href=&quot;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-6&quot;&gt;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-6&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=135222&amp;parent=590822</guid>
    </item>
    <item>
      <category>MSA-09-0014: mimeTeX vulnerabilities</category>
      <title>MSA-09-0014: mimeTeX vulnerabilities</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=128474&amp;parent=562732</link>
      <pubDate>Sun, 19 Jul 2009 18:04:10 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;mimeTeX vulnerabilities
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity/Risk:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; all
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;upstream - http://www.ocert.org/advisories/ocert-2009-010.html
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-19832&quot;&gt;MDL-19832&lt;/a&gt;, CVE-2009-1382
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to latest weekly built, stable CVS, nightly build or copy new mimetex.* executables into any older release
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;disable tex and algebra filters
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;John Forkosh fixed several serious vulnerabilities in mimeTeX binary which is used in Moodle by TeX and Algebra filter.  This was rated as &quot;critical&quot; upstream, however the risk is slightly less on Moodle because this filter can be disabled (and is disabled by default).  In addition, the vulnerability is only exposed to valid users who have logged in to Moodle.&lt;/p&gt;

&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=128474&amp;parent=562732</guid>
    </item>
    <item>
      <category>MSA-09-0013: Customised PhpMyAdmin upgraded to 2.11.9.5</category>
      <title>MSA-09-0013: Customised PhpMyAdmin upgraded to 2.11.9.5</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=123860&amp;parent=542780</link>
      <pubDate>Wed, 20 May 2009 11:05:17 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;Customised PhpMyAdmin upgraded to 2.11.9.5
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; all
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;upstream - PMASA-2009-1, PMASA-2009-2, PMASA-2009-3, PMASA-2009-4
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-19234&quot;&gt;MDL-19234&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; Install latest package from &lt;a href=&quot;http://moodle.org/mod/data/view.php?d=13&amp;rid=448&quot;&gt;http://moodle.org/mod/data/view.php?d=13&amp;amp;rid=448&lt;/a&gt; or cvs
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Workaround:
    &lt;/td&gt;
    &lt;td&gt;delete admin/mysql/*
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;&lt;a href=&quot;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-1&quot;&gt;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-1&lt;br /&gt;&lt;/a&gt; &lt;a href=&quot;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-2&quot;&gt;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-2&lt;br /&gt;&lt;/a&gt; &lt;a href=&quot;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-3&quot;&gt;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-3&lt;br /&gt;&lt;/a&gt; &lt;a href=&quot;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-4&quot;&gt;http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2009-4&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Please note that some of these vulnerabilities may not be exploitable due to our specific integration changes.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=123860&amp;parent=542780</guid>
    </item>
    <item>
      <category>MSA-09-0012: SQL injections when importing outcomes</category>
      <title>MSA-09-0012: SQL injections when importing outcomes</title>
      <link>http://moodle.org/mod/forum/discuss.php?d=123858&amp;parent=542778</link>
      <pubDate>Wed, 20 May 2009 11:00:40 GMT</pubDate>
      <dc:creator>Petr Škoda (skodak)</dc:creator>
      <description>by Petr Škoda (skodak). &amp;nbsp;&lt;p&gt;
&lt;table&gt;&lt;tbody&gt;
  &lt;tr&gt;
    &lt;td&gt;Topic:
    &lt;/td&gt;
    &lt;td&gt;SQL injections when importing outcomes
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Severity:
    &lt;/td&gt;
    &lt;td&gt;Major
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Versions affected:
    &lt;/td&gt;
    &lt;td&gt; &amp;lt; 1.9.5
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Reported by:
    &lt;/td&gt;
    &lt;td&gt;internal review
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Issue no.:
    &lt;/td&gt;
    &lt;td&gt; &lt;a title=&quot;Auto-link to Moodle Tracker&quot; href=&quot;http://tracker.moodle.org/browse/MDL-19036&quot;&gt;MDL-19036&lt;/a&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Solution:
    &lt;/td&gt;
    &lt;td&gt; upgrade to 1.9.5
    &lt;/td&gt;
  &lt;/tr&gt; &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Description:&lt;/strong&gt;&lt;br /&gt;When reviewing the import outcomes code, it was discovered that incorrect coding allowed SQL injections. By default only trusted users are allowed to use this part of gradebook. It can not be exploited by students.&lt;/p&gt;&lt;/p&gt;</description>
      <guid isPermaLink="true">http://moodle.org/mod/forum/discuss.php?d=123858&amp;parent=542778</guid>
    </item>
  </channel>
</rss>