Please Merge Moodle 1.9.4 in Maverick with Debian Unstable 1.9.9 - active security vulnerability

Bug #640572 reported by intel352
20
This bug affects 3 people
Affects Status Importance Assigned to Milestone
moodle (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

The current stable Moodle release is 1.9.9, yet the current release in Ubuntu is 1.9.4.
The maintainer of the Moodle package, per Launchpad, is not active with Launchpad.
How can we get this updated?

CVE References

Revision history for this message
intel352 (intel352) wrote :
Download full text (71.4 KiB)

Changelog since 1.9.4:

  1.9.9 ( 08/Jun/10 | Release Notes)

     MDL-22654 FIXED HTMLPurify is replacing line breaks with \n causing comparisons after cleaning to always fail
     MDL-22181 FIXED Assignment ID number field changing when student submits assignment
     MDL-22531 FIXED Source Code bug in accesslib.php
     MDL-22680 FIXED setnew_password_and_mail in Moodlelib updates the database without using salt
     MDL-21444 FIXED AICC: total_time is always accumulated over the record representing the first attempt, opposite to the logic implemented for SCORM tracked actitivties
     MDL-22098 FIXED Broken caching in the grade item classes leads ot O(n) DB queries in the grader report
     MDL-24033 FIXED Database module allows you to start adding new entries even if the maximum has already been reached
     MDL-23663 FIXED Editing teachers cannot import in Moodle 1.9.9
     MDL-22518 FIXED Group dropdowns prevent tab from functioning correctly
     MDL-10906 FIXED No option in user profile ot specify local drive for local files
     MDL-21987 FIXED Problem with repeat grade imports when is_overridable_item is true
     MDL-22257 FIXED Quiz reports run out of memory on a course with 16000 users
     MDL-20586 FIXED Recent activity reports quiz grade regardless of review settings for the quiz.
     MDL-21379 FIXED SCORM 2004 JS Errors
     MDL-21423 FIXED SCORM attempts do not record "first access" or "start time", though that's what Moodle labels them.
     MDL-21828 FIXED SQL error with ambiguous column definition
     MDL-22588 FIXED Wrong courseid in mdl_scale on course restore
     MDL-22034 NOT A BUG Restore a Backup from another Moodle fail
     MDL-22176 FIXED Backup/Restore does not change manually added links to the same course
     MDL-22301 FIXED Bug with SCORM backup naming
     MDL-23120 FIXED Catchable fatal error in Language file lv_utf8/data.php
     MDL-19880 FIXED Course import runs out of memory when user has update capability on large number of courses
     MDL-22154 FIXED Flash detection is made on every page load with AJAX call to environment.php script (meant be done only once per session)
     MDL-18835 FIXED Human-readable time periods in SCORM reports
     MDL-22175 FIXED Improve unit test failure display
     MDL-22575 FIXED International (English) name of the language should be part of langconfig.php
     MDL-18202 FIXED JavaScript Error on Session Resume
     MDL-24054 FIXED Multilang filter not working in answers
     MDL-22241 FIXED Oracle error in questiontype.php on line 919 (invalid character)
     MDL-22726 FIXED Problem restoring backup with hotpot (Jmatch and Jmix)
     MDL-10197 FIXED Quality improvement of Tex-images
     MDL-22410 FIXED The $grader variable is defined twice in "quiz_get_recent_mod_activity" in mod/quiz/lib.php
     MDL-18689 FIXED Typos in auth/cas/auth.php
     MDL-22017 FIXED Unit test failure from test_usergetdate
     MDL-22046 FIXED When Attempts grading is set to "Last Attempt", an incomplete exam causes a user's grade to show as zero on so...

Revision history for this message
David Sugar (dyfet-deactivatedaccount) wrote :

Most relevant is that there is a well known cross-site scripting vulnerability in 1.9.x versions < 1.9.9 (per Debian bug #586280). Hence this is a security issue, not just a question of bugfixes. This has been updated in debian already. I see we do carry some ubuntu-specific patches which have to be reviewed.

summary: - Moodle needs to be updated to 1.9.9 (currently at 1.9.4)
+ Please Merge Moodle 1.9.4 in Maverick with Debian Unstable 1.9.9 -
+ active security vulnerability
Revision history for this message
Tomasz (Tomek) Muras (zabuch) wrote :

The package in Debian has been re-written from scratch for 1.9.9.
If there is still any need for Ubuntu-specific patches, I'd be happy to include them in a Debian package, so the source for both packages is the same.

Tomasz Muras

Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (3.9 KiB)

This bug was fixed in the package moodle - 1.9.9.dfsg2-2

---------------
moodle (1.9.9.dfsg2-2) unstable; urgency=low

  * Added Romanian translation
  * Updated Japanese translation (closes: #596820)
  * Backporting security fixes from Moodle 1.9.10 (closes: #601384)
     - Updated embedded CAS to 1.1.3
     - Added patch for MDL-24523:
       clean_text() not filtering text in markdown format
     - Added patch for MDL-24810 and upgraded customized HTML Purifier to 4.2.0
     - Added patch for MDL-24258:
       students can delete their forum posts later than $CFG->maxeditingtime
       under certain conditions
     - Added patch for MDL-23377:
       Can't delete quiz attempts in course without enrolled students

moodle (1.9.9.dfsg2-1) unstable; urgency=low

  * Enable HTML purifier by default
  * Added Janapenese translation (closes: #593808)
  * Removed from source swf files without a source code
    and added README.source
  * Updated bundled HTML purifier library - fix for
    CVE-2010-2479 (closes: #593301)

moodle (1.9.9.dfsg-1) unstable; urgency=low

  [ Jonathan Wiltshire ]
  * Debconf templates and debian/control reviewed by the debian-l10n-
    english team as part of the Smith review project. Closes: #588871
  * Debconf translation updates:
     - Russian (closes: #589247)
     - Czech (closes: #589265)
     - Swedish (closes: #589270)
     - French (closes: #589510)
     - German (closes: #590120)
     - Spanish (closes: #590449)
     - Portugese (closes: #590556)

  [ Tomasz Muras ]
  * New debconf translation - Polish
  * Removed .swf files as non-free (closes: #591201)
  * Fixed generation of config.php for postgres (thanks Giles Westwood)

moodle (1.9.9-2) unstable; urgency=low

  * Fixed JS includes for YUI library (closes: #589612)
  * Bumped standards version to 3.9.0
  * Moved BSD licenses into copyright (fixes lintian warning)
  * Setting DM-Upload-Allowed as agreed with Xavier Oswald <email address hidden>

moodle (1.9.9-1) unstable; urgency=low

  * Rewritten debian/rules
  * Removed unnecessary usr/share/moodle/update-notifier
  * New Upstream Version: 1.9.9
  * New upstream fixes CVE-2010-1619 (closes: #585425)
  * New upstream fixes MSA-10-0011 (closes: #586280)

moodle (1.9.8-1) unstable; urgency=low

  [Tomasz Muras]
  * New Maintainer (closes: #581229, #574969).
  * New Upstream Version (closes: #475535).
  * Added information about flvplayer to copyright (closes: #526543).
  * phpCAS XSS vulnerability fixed in mainstream Moodle 1.9.8 (closes: #574757).
  * Several security issues fixed in upstream (closes: #576189).
  * Moodle depends on postgresql or MySQL (closes: #551399).
  * Re-written to use dbconfig-common (closes: #302205).
  * Updated copyright with two new entires (closes: #526543).
  * Drop use of wwwconfig (closes: #389502).
  * Package is now not creating Apache config automatically (closes: #555672).
    It's up to the user to configure the webserver but package provides the
    templates.
  * Added "allow from localhost" (closes: #551402).
  * Asking for wwwroot during the installation (closes: #302207).
  * Removing nusoap as it's not necessary for PHP 5 (closes: #529573).

  [Xavier Oswald]
  *...

Read more...

Changed in moodle (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Related questions

Remote bug watches

Bug watches keep track of this bug in other bug trackers.