Vulnerability Comparisons

Vulnerability Comparisons

de către Dave Bethany-
Număr de răspunsuri: 9

You may all wish to review Security Focus' vulnerability review, comparing Moodle to BB and WebCT. Amazingly, it states that the latest Moodle version shows no vulnerabilities, while the other folks do...hmmm, curiouser and curiouser...

http://securityfocus.com/bid/vendor/

dave

Media notelor: -
Ca răspuns la Dave Bethany

SF has one left for Moodle

de către Michael Penney-
if this is closed in 1.4.2+:

http://securityfocus.com/bid/11608

we should report it to them.

SF is still reporting on this issue :

Moodle is affected by a remote SQL injection vulnerability in its glossary module. This issue is due to a failure of the application to properly sanitize user-supplier input.

But the release notes for 1.4.2 report:
Some important security fixes
  • Better checking/cleaning of script parameters used in quite a few areas throughout Moodle (a BIG thanks to Petr Skoda for his recent security audit!)
  • Quoted some SQL parameters in the glossary module to prevent possible injection
SF is saying:
Although it has been reported that this issue is fixed in version 1.4.2 of the affected software, this is not confirmed. Please contact the vendor for more information.
Does anyone have more info. on this issue?

Ca răspuns la Michael Penney

Re: SF has one left for Moodle

de către Martin Dougiamas-
Imaginea Core developers Imaginea Documentation writers Imaginea Moodle HQ Imaginea Particularly helpful Moodlers Imaginea Plugin developers Imaginea Testers
Well, yes, it was definitely fixed.  I don't need to lie about such stuff in the release notes... încurcat
Ca răspuns la Martin Dougiamas

Re: SF has one left for Moodle

de către Michael Penney-

Hi Martin, sorry, didn't mean to imply anything, I was just seeking confirmation. Does SF take a while to change their reports? I can imagine they may be a bit left behind by the speed with which these things get fixed in the OSS communitysurâs.

This is part of a big debate wrt security, a pretty big issue with our (California's) privacy laws, some of these holes in BB and WebCT are pretty alarming if they are still open.

Anyway, thanks for laying my fears to rest for at least one of the LMS's I'm responsible forsurâs.

Ca răspuns la Michael Penney

Re: SF has one left for Moodle

de către Martin Dougiamas-
Imaginea Core developers Imaginea Documentation writers Imaginea Moodle HQ Imaginea Particularly helpful Moodlers Imaginea Plugin developers Imaginea Testers
Sorry, my annoyance was directed at them, not you! rânjet mare It's the "vendor says it's fixed but we have not confirmed it" attitude. I've already emailed them to confirm that fix (again).

Anyway, wait till you see the list of fixes in 1.4.3!   limba scoasă   We (and in particular Petr Skoda!) have been busy over at security.moodle.org
Ca răspuns la Dave Bethany

Re: Vulnerability Comparisons

de către Mark Stevens-
Dave,

I can't find the page where it says there are no current vulnerabilities in Moodle.  (Vendor Moodle produces a list of old issues.)
Ca răspuns la Mark Stevens

Re: Vulnerability Comparisons

de către Michael Penney-

It doesn't appear to say that in so many words. You have to look at the issues and see if they are closed. They only one they still have open is the glossary one, which was closed in 1.4.2 (see Martin's post on this thread).

The 2 Blackboard holes and the one WebCT that are still open are pretty alarming, as there is no report whether this is closed in BB 6.1 or WebCT CE (and those are core holes, also, not ones you could address by disabling a module).

That you could access someone else's digital drop box by guessing the URI on Blackboard is particularly alarming. Now that I've seen this we are going to have to spend a bunch of time seeing whether it is fixed and figuring out what to do about it if it isn't.

Ca răspuns la Michael Penney

Re: Vulnerability Comparisons

de către Mark Stevens-
Michael,

So, they don't tell you about the vulnerability and it's up to you to find out and check with them and work on your on temporary fix while you wait for the patch... and since it's closed source, you are limited as to what you can do...

That's an eye-opener for me, and one more reason to go open source.

I feel like ending each post by thanking the entire Moodle community... and on this one Dave and Michael and can't leave out Peter and Martin!

Thanks!
Ca răspuns la Dave Bethany

Re: Vulnerability Comparisons

de către Dave Bethany-

This is strange...yesterday when I looked it showed the various releases and clearly stated that 1.4.2 had no vulnerability issues. Maybe I clicked on a different area. Its that old age thing.

Dave