Vulnerability Comparisons

Vulnerability Comparisons

by Dave Bethany -
Number of replies: 9

You may all wish to review Security Focus' vulnerability review, comparing Moodle to BB and WebCT. Amazingly, it states that the latest Moodle version shows no vulnerabilities, while the other folks do...hmmm, curiouser and curiouser...

http://securityfocus.com/bid/vendor/

dave

Average of ratings: -
In reply to Dave Bethany

SF has one left for Moodle

by Michael Penney -
if this is closed in 1.4.2+:

http://securityfocus.com/bid/11608

we should report it to them.

SF is still reporting on this issue :

Moodle is affected by a remote SQL injection vulnerability in its glossary module. This issue is due to a failure of the application to properly sanitize user-supplier input.

But the release notes for 1.4.2 report:
Some important security fixes
  • Better checking/cleaning of script parameters used in quite a few areas throughout Moodle (a BIG thanks to Petr Skoda for his recent security audit!)
  • Quoted some SQL parameters in the glossary module to prevent possible injection
SF is saying:
Although it has been reported that this issue is fixed in version 1.4.2 of the affected software, this is not confirmed. Please contact the vendor for more information.
Does anyone have more info. on this issue?

In reply to Michael Penney

Re: SF has one left for Moodle

by Martin Dougiamas -
Picture of Core developers Picture of Documentation writers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers
Well, yes, it was definitely fixed.  I don't need to lie about such stuff in the release notes... mixed
In reply to Martin Dougiamas

Re: SF has one left for Moodle

by Michael Penney -

Hi Martin, sorry, didn't mean to imply anything, I was just seeking confirmation. Does SF take a while to change their reports? I can imagine they may be a bit left behind by the speed with which these things get fixed in the OSS communitysmile.

This is part of a big debate wrt security, a pretty big issue with our (California's) privacy laws, some of these holes in BB and WebCT are pretty alarming if they are still open.

Anyway, thanks for laying my fears to rest for at least one of the LMS's I'm responsible forsmile.

In reply to Michael Penney

Re: SF has one left for Moodle

by Martin Dougiamas -
Picture of Core developers Picture of Documentation writers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers
Sorry, my annoyance was directed at them, not you! big grin It's the "vendor says it's fixed but we have not confirmed it" attitude. I've already emailed them to confirm that fix (again).

Anyway, wait till you see the list of fixes in 1.4.3!   tongueout   We (and in particular Petr Skoda!) have been busy over at security.moodle.org
In reply to Dave Bethany

Re: Vulnerability Comparisons

by Mark Stevens -
Dave,

I can't find the page where it says there are no current vulnerabilities in Moodle.  (Vendor Moodle produces a list of old issues.)
In reply to Mark Stevens

Re: Vulnerability Comparisons

by Michael Penney -

It doesn't appear to say that in so many words. You have to look at the issues and see if they are closed. They only one they still have open is the glossary one, which was closed in 1.4.2 (see Martin's post on this thread).

The 2 Blackboard holes and the one WebCT that are still open are pretty alarming, as there is no report whether this is closed in BB 6.1 or WebCT CE (and those are core holes, also, not ones you could address by disabling a module).

That you could access someone else's digital drop box by guessing the URI on Blackboard is particularly alarming. Now that I've seen this we are going to have to spend a bunch of time seeing whether it is fixed and figuring out what to do about it if it isn't.

In reply to Michael Penney

Re: Vulnerability Comparisons

by Mark Stevens -
Michael,

So, they don't tell you about the vulnerability and it's up to you to find out and check with them and work on your on temporary fix while you wait for the patch... and since it's closed source, you are limited as to what you can do...

That's an eye-opener for me, and one more reason to go open source.

I feel like ending each post by thanking the entire Moodle community... and on this one Dave and Michael and can't leave out Peter and Martin!

Thanks!
In reply to Dave Bethany

Re: Vulnerability Comparisons

by Dave Bethany -

This is strange...yesterday when I looked it showed the various releases and clearly stated that 1.4.2 had no vulnerability issues. Maybe I clicked on a different area. Its that old age thing.

Dave