Vulnerability Comparisons

Vulnerability Comparisons

ved Dave Bethany -
Antal besvarelser: 9

You may all wish to review Security Focus' vulnerability review, comparing Moodle to BB and WebCT. Amazingly, it states that the latest Moodle version shows no vulnerabilities, while the other folks do...hmmm, curiouser and curiouser...

http://securityfocus.com/bid/vendor/

dave

Gennemsnitsbedømmelse: -
I svar til Dave Bethany

SF has one left for Moodle

ved Michael Penney -
if this is closed in 1.4.2+:

http://securityfocus.com/bid/11608

we should report it to them.

SF is still reporting on this issue :

Moodle is affected by a remote SQL injection vulnerability in its glossary module. This issue is due to a failure of the application to properly sanitize user-supplier input.

But the release notes for 1.4.2 report:
Some important security fixes
  • Better checking/cleaning of script parameters used in quite a few areas throughout Moodle (a BIG thanks to Petr Skoda for his recent security audit!)
  • Quoted some SQL parameters in the glossary module to prevent possible injection
SF is saying:
Although it has been reported that this issue is fixed in version 1.4.2 of the affected software, this is not confirmed. Please contact the vendor for more information.
Does anyone have more info. on this issue?

I svar til Michael Penney

Re: SF has one left for Moodle

ved Martin Dougiamas -
Billede af Core developers Billede af Documentation writers Billede af Moodle HQ Billede af Particularly helpful Moodlers Billede af Plugin developers Billede af Testers
Well, yes, it was definitely fixed.  I don't need to lie about such stuff in the release notes... rådvild
I svar til Martin Dougiamas

Re: SF has one left for Moodle

ved Michael Penney -

Hi Martin, sorry, didn't mean to imply anything, I was just seeking confirmation. Does SF take a while to change their reports? I can imagine they may be a bit left behind by the speed with which these things get fixed in the OSS communitysmiler.

This is part of a big debate wrt security, a pretty big issue with our (California's) privacy laws, some of these holes in BB and WebCT are pretty alarming if they are still open.

Anyway, thanks for laying my fears to rest for at least one of the LMS's I'm responsible forsmiler.

I svar til Michael Penney

Re: SF has one left for Moodle

ved Martin Dougiamas -
Billede af Core developers Billede af Documentation writers Billede af Moodle HQ Billede af Particularly helpful Moodlers Billede af Plugin developers Billede af Testers
Sorry, my annoyance was directed at them, not you! stort grin It's the "vendor says it's fixed but we have not confirmed it" attitude. I've already emailed them to confirm that fix (again).

Anyway, wait till you see the list of fixes in 1.4.3!   rækker tunge   We (and in particular Petr Skoda!) have been busy over at security.moodle.org
I svar til Dave Bethany

Re: Vulnerability Comparisons

ved Mark Stevens -
Dave,

I can't find the page where it says there are no current vulnerabilities in Moodle.  (Vendor Moodle produces a list of old issues.)
I svar til Mark Stevens

Re: Vulnerability Comparisons

ved Michael Penney -

It doesn't appear to say that in so many words. You have to look at the issues and see if they are closed. They only one they still have open is the glossary one, which was closed in 1.4.2 (see Martin's post on this thread).

The 2 Blackboard holes and the one WebCT that are still open are pretty alarming, as there is no report whether this is closed in BB 6.1 or WebCT CE (and those are core holes, also, not ones you could address by disabling a module).

That you could access someone else's digital drop box by guessing the URI on Blackboard is particularly alarming. Now that I've seen this we are going to have to spend a bunch of time seeing whether it is fixed and figuring out what to do about it if it isn't.

I svar til Michael Penney

Re: Vulnerability Comparisons

ved Mark Stevens -
Michael,

So, they don't tell you about the vulnerability and it's up to you to find out and check with them and work on your on temporary fix while you wait for the patch... and since it's closed source, you are limited as to what you can do...

That's an eye-opener for me, and one more reason to go open source.

I feel like ending each post by thanking the entire Moodle community... and on this one Dave and Michael and can't leave out Peter and Martin!

Thanks!
I svar til Dave Bethany

Re: Vulnerability Comparisons

ved Dave Bethany -

This is strange...yesterday when I looked it showed the various releases and clearly stated that 1.4.2 had no vulnerability issues. Maybe I clicked on a different area. Its that old age thing.

Dave