Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://docs.moodle.org/en/Moodle_1.9.7_release_notes | patch |
http://docs.moodle.org/en/Moodle_1.8.11_release_notes | patch |
http://moodle.org/mod/forum/discuss.php?d=139105 | |
http://www.vupen.com/english/advisories/2009/3455 | vdb entry patch vendor advisory |
http://secunia.com/advisories/37614 | third party advisory vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00730.html | vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00704.html | vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00751.html | vendor advisory |
http://www.securityfocus.com/bid/37244 | vdb entry patch |