Date: Sat, 31 Mar 2018 08:17:58 +0000 (UTC) From: Wen Heping <wen@FreeBSD.org> To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r466031 - head/security/vuxml Message-ID: <201803310817.w2V8Hwk1009403@repo.freebsd.org>
next in thread | raw e-mail | index | archive | help
Author: wen Date: Sat Mar 31 08:17:58 2018 New Revision: 466031 URL: https://svnweb.freebsd.org/changeset/ports/466031 Log: - Document Moodle vulnerability Modified: head/security/vuxml/vuln.xml Modified: head/security/vuxml/vuln.xml ============================================================================== --- head/security/vuxml/vuln.xml Sat Mar 31 08:08:19 2018 (r466030) +++ head/security/vuxml/vuln.xml Sat Mar 31 08:17:58 2018 (r466031) @@ -58,6 +58,48 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="cdb4d962-34f9-11e8-92db-080027907385"> + <topic>moodle -- multiple vulnerabilities</topic> + <affects> + <package> + <name>moodle31</name> + <range><lt>3.1.11</lt></range> + </package> + <package> + <name>moodle32</name> + <range><lt>3.2.8</lt></range> + </package> + <package> + <name>moodle33</name> + <range><lt>3.3.5</lt></range> + </package> + <package> + <name>moodle34</name> + <range><lt>3.4.2</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>moodle reports:</p> + <blockquote cite="https://moodle.org/mod/forum/discuss.php?d=367938"> + <p>Unauthenticated users can trigger custom messages to admin via + paypal enrol script.</p> + <p>Suspended users with OAuth 2 authentication method can still log in to + the site.</p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2018-1081</cvename> + <cvename>CVE-2018-1082</cvename> + <url>https://moodle.org/mod/forum/discuss.php?d=367938</url> + </references> + <dates> + <discovery>2018-03-14</discovery> + <entry>2018-03-31</entry> + </dates> + </vuln> + <vuln vid="eb69bcf2-18ef-4aa2-bb0c-83b263364089"> <topic>ruby -- multiple vulnerabilities</topic> <affects>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201803310817.w2V8Hwk1009403>