|
|
| |
|
| |
moodle: insecure temp file
| Package(s): | moodle |
CVE #(s): | CVE-2008-5153
|
| Created: | January 22, 2009 |
Updated: | June 25, 2009 |
| Description: |
moodle has an insecure temp file vulnerability. From the
Red Hat Bug entry:
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite
arbitrary files via a symlink attack on the
/tmp/spell-check-debug.log, /tmp/spell-check-before, or
/tmp/spell-check-after temporary file. |
| Alerts: |
|
( Log in to post comments)
|
|
|