Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 552636 - <www-apps/moodle-{2.6.11,2.7.8,2.8.6}: Multiple vulnerabilities (CVE-2015-{0211,0212,0213,0214,0215,0216,0217,0218,1493,2266,2267,2268,2269,2270,2271,2272,2273,3174,3175,3176,3177,3178,3179,3180,3181})
Summary: <www-apps/moodle-{2.6.11,2.7.8,2.8.6}: Multiple vulnerabilities (CVE-2015-{02...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-06-20 14:21 UTC by GLSAMaker/CVETool Bot
Modified: 2015-06-20 14:22 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2015-06-20 14:21:28 UTC
CVE-2015-3181 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3181):
  files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x
  before 2.7.8, and 2.8.x before 2.8.6 does not consider the
  moodle/user:manageownfiles capability before approving a private-file
  upload, which allows remote authenticated users to bypass intended
  file-management restrictions by using web services to perform uploads after
  this capability has been revoked.

CVE-2015-3180 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3180):
  lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x
  before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to
  obtain sensitive course-structure information by leveraging access to a
  student account with a suspended enrolment.

CVE-2015-3179 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3179):
  login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before
  2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass
  intended login restrictions by leveraging access to an unconfirmed suspended
  account.

CVE-2015-3178 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3178):
  Cross-site scripting (XSS) vulnerability in the external_format_text
  function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before
  2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote
  authenticated users to inject arbitrary web script or HTML into an external
  application via a crafted string that is visible to web services.

CVE-2015-3177 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3177):
  Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe
  capability before entering subscriptions to site-wide event-monitor rules,
  which allows remote authenticated users to obtain sensitive information via
  a subscription request.

CVE-2015-3176 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3176):
  The account-confirmation feature in login/confirm.php in Moodle through
  2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6
  allows remote attackers to obtain sensitive full-name information by
  attempting to self-register.

CVE-2015-3175 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3175):
  Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before
  2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to
  redirect users to arbitrary web sites and conduct phishing attacks via
  vectors involving an error page that links to a URL from an HTTP Referer
  header.

CVE-2015-3174 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3174):
  mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x
  before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for
  graders, which allows remote authenticated users to conduct cross-site
  scripting (XSS) attacks via crafted gradebook feedback during manual quiz
  grading.

CVE-2015-2273 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2273):
  Cross-site scripting (XSS) vulnerability in
  mod/quiz/report/statistics/statistics_question_table.php in Moodle through
  2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows
  remote authenticated users to inject arbitrary web script or HTML by
  leveraging the student role for a crafted quiz response.

CVE-2015-2272 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2272):
  login/token.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before
  2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass a
  forced-password-change requirement by creating a web-services token.

CVE-2015-2271 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2271):
  tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before
  2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag
  capability before proceeding with a flaginappropriate action, which allows
  remote authenticated users to bypass intended access restrictions via the
  "Flag as inappropriate" feature.

CVE-2015-2270 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2270):
  lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before
  2.7.6, and 2.8.x before 2.8.4, when the theme uses the blocks-regions
  feature, establishes the course state at an incorrect point in the
  login-validation process, which allows remote attackers to obtain sensitive
  course information via unspecified vectors.

CVE-2015-2269 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2269):
  Multiple cross-site scripting (XSS) vulnerabilities in
  lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x
  before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to
  inject arbitrary web script or HTML via a (1) alt or (2) title attribute in
  an IMG element.

CVE-2015-2268 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2268):
  filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9,
  2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users
  to cause a denial of service (CPU consumption or partial outage) via a
  crafted string that is matched against an improper regular expression.

CVE-2015-2267 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2267):
  mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6,
  and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended
  access restrictions and extract archives to arbitrary directories via a
  crafted dataroot value.

CVE-2015-2266 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2266):
  message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before
  2.7.6, and 2.8.x before 2.8.4 does not consider the
  moodle/site:readallmessages capability before accessing arbitrary
  conversations, which allows remote authenticated users to obtain sensitive
  personal-contact and unread-message-count information via a modified URL.

CVE-2015-1493 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1493):
  Directory traversal vulnerability in the min_get_slash_argument function in
  lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x
  before 2.7.5, and 2.8.x before 2.8.3 allows remote authenticated users to
  read arbitrary files via a .. (dot dot) in the file parameter, as
  demonstrated by reading PHP scripts.

CVE-2015-0218 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0218):
  Cross-site request forgery (CSRF) vulnerability in
  auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7,
  2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack
  the authentication of arbitrary users for requests that trigger a logout.

CVE-2015-0217 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0217):
  filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7,
  2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users
  to cause a denial of service (CPU consumption or partial outage) via a
  crafted string that is matched against an improper regular expression.

CVE-2015-0216 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0216):
  access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set
  the RISK_XSS bit for graders, which allows remote authenticated users to
  conduct cross-site scripting (XSS) attacks via crafted essay feedback.

CVE-2015-0215 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0215):
  calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x
  before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to
  obtain sensitive calendar-event information via a web-services request.

CVE-2015-0214 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0214):
  message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x
  before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to
  bypass a messaging-disabled setting via a web-services request, as
  demonstrated by a people-search request.

CVE-2015-0213 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0213):
  Multiple cross-site request forgery (CSRF) vulnerabilities in (1)
  editcategories.html and (2) editcategories.php in the Glossary module in
  Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x
  before 2.8.2 allow remote attackers to hijack the authentication of
  unspecified victims.

CVE-2015-0212 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0212):
  Cross-site scripting (XSS) vulnerability in course/pending.php in Moodle
  through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before
  2.8.2 allows remote authenticated users to inject arbitrary web script or
  HTML via a crafted course summary.

CVE-2015-0211 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0211):
  mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before
  2.7.4, and 2.8.x before 2.8.2 does not consider the
  moodle/course:manageactivities and mod/lti:addinstance capabilities before
  proceeding with registered-tool list searches, which allows remote
  authenticated users to obtain sensitive information via requests to the LTI
  Ajax service.
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2015-06-20 14:22:28 UTC
Fixed packages already in tree, vulnerable versions have been dropped. 

Closing noglsa for ~arch only.