Описание
Moodle vulnerable to symlink attack
spell-check-logic.cgi
in Moodle 1.9 before 1.9.4, 1.8 before 1.8.8, 1.7 before 1.7.7 and 1.6 before 1.6.9 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log
, (2) /tmp/spell-check-before
, or (3) /tmp/spell-check-after
temporary file.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2008-5153
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46708
- https://web.archive.org/web/20090821033319/http://secunia.com/advisories/33955
- https://web.archive.org/web/20110511083352/http://uvw.ru/report.sid.txt
- https://web.archive.org/web/20141121115305/http://www.securityfocus.com/bid/32402
- http://lists.debian.org/debian-devel/2008/08/msg00347.html
- http://www.debian.org/security/2009/dsa-1724
Пакеты
moodle/moodle
>= 1.9.0, < 1.9.4
1.9.4
moodle/moodle
>= 1.8.0, < 1.8.8
1.8.8
moodle/moodle
>= 1.7.0, < 1.7.7
1.7.7
moodle/moodle
>= 1.6.0, < 1.6.9
1.6.9
Связанные уязвимости
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.
spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite ...