Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <1109306790.230341270150395240.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Thu, 1 Apr 2010 15:33:15 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Request: moodle 1.9.8, 1.8.2


----- "Ludwig Nussel" <ludwig.nussel@...e.de> wrote:

> Hi,
> 
> Moodle 1.9.8 and 1.8.12 were released with security fixes:
> http://docs.moodle.org/en/Moodle_1.9.8_release_notes
> * MSA-10-0001 Vulnerability in KSES text cleaning
> * MSA-10-0002 XSS vulnerabilty in the phpcas module
> * MSA-10-0003 Disclosure of full user names
> * MSA-10-0004 Improved access control in course restore
> * MSA-10-0005 Incorrect validation of forms data
> * MSA-10-0006 SQL injection in Wiki module
> * MSA-10-0007 Reflective Cross Site Scripting (XSS) in the Moodle
> Global Search Engine
> * MSA-10-0008 Persistent XSS when using Login-as feature
> * MSA-10-0009 Session fixation prevention now turned on by default
> 

Steve,

I'm going to defer this one to MITRE.

On that note though, does someone have a Moodle contact, perhaps we could
get them to request CVE ids in private before a release, to avoid the
backlog that results.

The same holds for things like typo3, that seem to often have lots of flaws
all at once.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.