LWN.net Logo

moodle: insecure temp file

Package(s):moodle CVE #(s):CVE-2008-5153
Created:January 22, 2009 Updated:June 25, 2009
Description: moodle has an insecure temp file vulnerability. From the Red Hat Bug entry: spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/spell-check-debug.log, /tmp/spell-check-before, or /tmp/spell-check-after temporary file.
Alerts:
Ubuntu USN-791-1 2009-06-24
Fedora FEDORA-2009-3280 2009-04-02
Fedora FEDORA-2009-3283 2009-04-02
Debian DSA-1724-1 2009-02-13
Fedora FEDORA-2009-0819 2009-01-21
Fedora FEDORA-2009-0814 2009-01-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds