Vulnerability Comparisons

Vulnerability Comparisons

על ידי Dave Bethany בתאריך
מספר תגובות: 9

You may all wish to review Security Focus' vulnerability review, comparing Moodle to BB and WebCT. Amazingly, it states that the latest Moodle version shows no vulnerabilities, while the other folks do...hmmm, curiouser and curiouser...

http://securityfocus.com/bid/vendor/

dave

ממוצע דרוגים: -
בתגובה ל: Dave Bethany

SF has one left for Moodle

על ידי Michael Penney בתאריך
if this is closed in 1.4.2+:

http://securityfocus.com/bid/11608

we should report it to them.

SF is still reporting on this issue :

Moodle is affected by a remote SQL injection vulnerability in its glossary module. This issue is due to a failure of the application to properly sanitize user-supplier input.

But the release notes for 1.4.2 report:
Some important security fixes
  • Better checking/cleaning of script parameters used in quite a few areas throughout Moodle (a BIG thanks to Petr Skoda for his recent security audit!)
  • Quoted some SQL parameters in the glossary module to prevent possible injection
SF is saying:
Although it has been reported that this issue is fixed in version 1.4.2 of the affected software, this is not confirmed. Please contact the vendor for more information.
Does anyone have more info. on this issue?

בתגובה ל: Michael Penney

Re: SF has one left for Moodle

על ידי Martin Dougiamas בתאריך
תמונה של Core developers תמונה של Documentation writers תמונה של Moodle HQ תמונה של Particularly helpful Moodlers תמונה של Plugin developers תמונה של Testers
Well, yes, it was definitely fixed.  I don't need to lie about such stuff in the release notes... מעורב
בתגובה ל: Martin Dougiamas

Re: SF has one left for Moodle

על ידי Michael Penney בתאריך

Hi Martin, sorry, didn't mean to imply anything, I was just seeking confirmation. Does SF take a while to change their reports? I can imagine they may be a bit left behind by the speed with which these things get fixed in the OSS communityחיוך.

This is part of a big debate wrt security, a pretty big issue with our (California's) privacy laws, some of these holes in BB and WebCT are pretty alarming if they are still open.

Anyway, thanks for laying my fears to rest for at least one of the LMS's I'm responsible forחיוך.

בתגובה ל: Michael Penney

Re: SF has one left for Moodle

על ידי Martin Dougiamas בתאריך
תמונה של Core developers תמונה של Documentation writers תמונה של Moodle HQ תמונה של Particularly helpful Moodlers תמונה של Plugin developers תמונה של Testers
Sorry, my annoyance was directed at them, not you! חיוך גדול It's the "vendor says it's fixed but we have not confirmed it" attitude. I've already emailed them to confirm that fix (again).

Anyway, wait till you see the list of fixes in 1.4.3!   לשון בחוץ   We (and in particular Petr Skoda!) have been busy over at security.moodle.org
בתגובה ל: Dave Bethany

Re: Vulnerability Comparisons

על ידי Mark Stevens בתאריך
Dave,

I can't find the page where it says there are no current vulnerabilities in Moodle.  (Vendor Moodle produces a list of old issues.)
בתגובה ל: Mark Stevens

Re: Vulnerability Comparisons

על ידי Michael Penney בתאריך

It doesn't appear to say that in so many words. You have to look at the issues and see if they are closed. They only one they still have open is the glossary one, which was closed in 1.4.2 (see Martin's post on this thread).

The 2 Blackboard holes and the one WebCT that are still open are pretty alarming, as there is no report whether this is closed in BB 6.1 or WebCT CE (and those are core holes, also, not ones you could address by disabling a module).

That you could access someone else's digital drop box by guessing the URI on Blackboard is particularly alarming. Now that I've seen this we are going to have to spend a bunch of time seeing whether it is fixed and figuring out what to do about it if it isn't.

בתגובה ל: Michael Penney

Re: Vulnerability Comparisons

על ידי Mark Stevens בתאריך
Michael,

So, they don't tell you about the vulnerability and it's up to you to find out and check with them and work on your on temporary fix while you wait for the patch... and since it's closed source, you are limited as to what you can do...

That's an eye-opener for me, and one more reason to go open source.

I feel like ending each post by thanking the entire Moodle community... and on this one Dave and Michael and can't leave out Peter and Martin!

Thanks!
בתגובה ל: Dave Bethany

Re: Vulnerability Comparisons

על ידי Dave Bethany בתאריך

This is strange...yesterday when I looked it showed the various releases and clearly stated that 1.4.2 had no vulnerability issues. Maybe I clicked on a different area. Its that old age thing.

Dave