Moodle 'spell-check-logic.cgi' Insecure Temporary File Creation Vulnerability
BID:32402
Info
Moodle 'spell-check-logic.cgi' Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 32402 |
| Class: | Design Error |
| CVE: |
CVE-2008-5153 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 11 2008 12:00AM |
| Updated: | Apr 16 2015 05:42PM |
| Credit: | Dmitry E. Oboukhov |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Moodle moodle 1.9.3 Moodle moodle 1.8.7 Moodle moodle 1.8.5 Moodle moodle 1.8.4 Moodle moodle 1.8.3 Moodle moodle 1.8.2 Moodle moodle 1.7.6 Moodle moodle 1.7.5 Moodle moodle 1.7.4 Moodle moodle 1.7.3 Moodle moodle 1.7.2 Moodle moodle 1.7.1 Moodle moodle 1.6.8 Moodle moodle 1.6.7 Moodle moodle 1.6.6 Moodle moodle 1.6.5 Moodle moodle 1.6.4 Moodle moodle 1.6.3 Moodle moodle 1.6.2 Moodle moodle 1.6.1 Moodle moodle 1.6 dev Moodle moodle 1.6 Moodle moodle 1.9 Moodle moodle 1.7 Moodle moodle 1.6.1 + Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Moodle moodle 1.9.4 Moodle moodle 1.8.8 Moodle moodle 1.7.7 Moodle moodle 1.6.9 |
Discussion
Moodle 'spell-check-logic.cgi' Insecure Temporary File Creation Vulnerability
Moodle creates temporary files in an insecure manner.
An attacker with local access could perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Moodle 1.8.2 is vulnerable; other versions may also be affected.
Moodle creates temporary files in an insecure manner.
An attacker with local access could perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
Moodle 1.8.2 is vulnerable; other versions may also be affected.
Exploit / POC
Moodle 'spell-check-logic.cgi' Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to launch attacks.
An attacker uses readily available commands to launch attacks.
Solution / Fix
Moodle 'spell-check-logic.cgi' Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 arm
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.10 powerpc
Debian Linux 4.0 powerpc
Ubuntu Ubuntu Linux 8.10 i386
Ubuntu Ubuntu Linux 8.04 LTS sparc
Debian Linux 4.0 m68k
Ubuntu Ubuntu Linux 8.04 LTS amd64
Ubuntu Ubuntu Linux 8.04 LTS lpia
Ubuntu Ubuntu Linux 8.10 lpia
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Ubuntu Ubuntu Linux 8.10 sparc
Debian Linux 4.0 alpha
Debian Linux 4.0
Ubuntu Ubuntu Linux 8.04 LTS i386
Debian Linux 4.0 mipsel
Ubuntu Ubuntu Linux 8.10 amd64
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Solution:
Updates are available. Please see the references for more information.
Debian Linux 4.0 arm
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Debian Linux 4.0 powerpc
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Ubuntu Ubuntu Linux 8.10 i386
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Debian Linux 4.0 m68k
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Ubuntu Ubuntu Linux 8.10 lpia
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Debian Linux 4.0 amd64
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Debian Linux 4.0 ia-32
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Debian Linux 4.0 hppa
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Debian Linux 4.0 sparc
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Debian Linux 4.0 s/390
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Debian Linux 4.0 alpha
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Debian Linux 4.0
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS i386
-
Ubuntu moodle_1.8.2-1ubuntu4.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1ubu ntu4.2_all.deb
Debian Linux 4.0 mipsel
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Ubuntu Ubuntu Linux 8.10 amd64
-
Ubuntu moodle_1.8.2-1.2ubuntu2.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/m/moodle/moodle_1.8.2-1.2u buntu2.1_all.deb
Debian Linux 4.0 ia-64
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
Debian Linux 4.0 mips
-
Debian moodle_1.6.3-2+etch2_all.deb
http://security.debian.org/pool/updates/main/m/moodle/moodle_1.6.3-2+e tch2_all.deb
References
Moodle 'spell-check-logic.cgi' Insecure Temporary File Creation Vulnerability
References:
References:
- Moodle Homepage (Moodle)
- Moodle Security (Moodle)
- Re: Possible mass bug filing: The possibility of attack with the help of symlink (Dmitry E. Oboukhov)