CVE-2008-5153

Publication date 18 November 2008

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

Read the notes from the security team

Status

Package Ubuntu Release Status
moodle 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Fixed 1.8.2-1.2ubuntu2.1
8.04 LTS hardy
Fixed 1.8.2-1ubuntu4.2
7.10 gutsy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

Notes


jdstrand

per Debian, must manually edit the file to execute affected code

References

Related Ubuntu Security Notices (USN)

    • USN-791-1
    • Moodle vulnerabilities
    • 24 June 2009

Other references