Note: You are currently viewing documentation for Moodle 1.9. Up-to-date documentation for the latest stable version is available here: Moodle 1.9.4 release notes.

Moodle 1.9.4 release notes: Difference between revisions

From MoodleDocs
No edit summary
 
Line 20: Line 20:


===Security issues===
===Security issues===
* [http://moodle.org/mod/forum/discuss.php?d=115523 MSA-09-0001]
* [http://moodle.org/mod/forum/discuss.php?d=115523 MSA-09-0001] No way easy to remove pictures of deleted users
* [http://moodle.org/mod/forum/discuss.php?d=115524 MSA-09-0002]
* [http://moodle.org/mod/forum/discuss.php?d=115524 MSA-09-0002] User pix disclosure
* [http://moodle.org/mod/forum/discuss.php?d=115525 MSA-09-0003]
* [http://moodle.org/mod/forum/discuss.php?d=115525 MSA-09-0003] Vulnerability in Snoopy 1.2.3
* [http://moodle.org/mod/forum/discuss.php?d=115526 MSA-09-0004]
* [http://moodle.org/mod/forum/discuss.php?d=115526 MSA-09-0004] XSS vulnerabilities in HTML blocks if "Login as" used
* [http://moodle.org/mod/forum/discuss.php?d=115527 MSA-09-0005]
* [http://moodle.org/mod/forum/discuss.php?d=115527 MSA-09-0005] Moodle 'spell-check-logic.cgi' Insecure Temporary File Creation Vulnerability
* [http://moodle.org/mod/forum/discuss.php?d=115528 MSA-09-0006]
* [http://moodle.org/mod/forum/discuss.php?d=115528 MSA-09-0006] Calendar export may allow brute force attacks
* [http://moodle.org/mod/forum/discuss.php?d=115529 MSA-09-0007]
* [http://moodle.org/mod/forum/discuss.php?d=115529 MSA-09-0007] Missing input validation in logs allows potential XSS attacks
* [http://moodle.org/mod/forum/discuss.php?d=115532 MSA-09-0008]
* [http://moodle.org/mod/forum/discuss.php?d=115532 MSA-09-0008] CSRF vulnerability in forum code


===New language strings file===
===New language strings file===

Latest revision as of 21:41, 5 November 2009

Release date: 28th January 2009

Here is the full list of fixed issues in 1.9.4.

Highlights

Security issues

  • MSA-09-0001 No way easy to remove pictures of deleted users
  • MSA-09-0002 User pix disclosure
  • MSA-09-0003 Vulnerability in Snoopy 1.2.3
  • MSA-09-0004 XSS vulnerabilities in HTML blocks if "Login as" used
  • MSA-09-0005 Moodle 'spell-check-logic.cgi' Insecure Temporary File Creation Vulnerability
  • MSA-09-0006 Calendar export may allow brute force attacks
  • MSA-09-0007 Missing input validation in logs allows potential XSS attacks
  • MSA-09-0008 CSRF vulnerability in forum code

New language strings file

  • report_security.php

New language pack

  • Kazakh - Калима Туенбаева

(See Translation credits for additional details.)

Known problems and regressions

  • New Security overview report on large sites extremely slow and overloading database server MDL-18040 - update to latest weekly or copy /admin/report/security/* files from latest weekly

See also