Synopsis
The remote Fedora host is missing a security update.
Description
Moodle upstream has released latest stable versions (1.9.7 and 1.8.11), fixing multiple security issues. The list for 1.9.7 release:
-------------------------- Security issues * MSA-09-0022 - Multiple CSRF problems fixed * MSA-09-0023 - Fixed user account disclosure in LAMS module * MSA-09-0024 - Fixed insufficient access control in Glossary module
  - MSA-09-0025 - Unneeded MD5 hashes removed from user     table * MSA-09-0026 - Fixed invalid application access     control in MNET interface * MSA-09-0027 - Ensured login     information is always sent secured when using SSL for     logins * MSA-09-0028 - Passwords and secrets are no     longer ever saved in backups, new backup capabilities     moodle/backup:userinfo and moodle/restore:userinfo for     controlling who can backup/restore user data, new checks     in the security overview report help admins identify     dangerous backup permissions * MSA-09-0029 - A strong     password policy is now enabled by default, enabling     password salt in encouraged in config.php, admins are     forced to change password after the upgrade and admins     can force password change on other users via Bulk user     actions * MSA-09-0030 - New detection of insecure Flash     player plugins, Moodle won't serve Flash to insecure     plugins * MSA-09-0031 - Fixed SQL injection in SCORM     module The list for 1.8.11 release:
    ---------------------------- Security issues *     MSA-09-0022 - Multiple CSRF problems fixed * MSA-09-0023
    - Fixed user account disclosure in LAMS module *     MSA-09-0024 - Fixed insufficient access control in     Glossary module * MSA-09-0025 - Unneeded MD5 hashes     removed from user table * MSA-09-0026 - Fixed invalid     application access control in MNET interface *     MSA-09-0027 - Ensured login information is always sent     secured when using SSL for logins * MSA-09-0028 -     Passwords and secrets are no longer ever saved in     backups, new backup capabilities moodle/backup:userinfo     and moodle/restore:userinfo for controlling who can     backup/restore user data * MSA-09-0029 - Enabling a     password salt in encouraged in config.php and admins are     forced to change password after the upgrade *     MSA-09-0031 - Fixed SQL injection in SCORM module     References: -----------     http://docs.moodle.org/en/Moodle_1.9.7_release_notes     http://docs.moodle.org/en/Moodle_1.8.11_release_notes     CVE Request: ------------     http://www.openwall.com/lists/oss-security/2009/12/06/1
Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
Solution
Update the affected moodle package.
Plugin Details
File Name: fedora_2009-13080.nasl
Agent: unix
Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Vulnerability Information
CPE: cpe:/o:fedoraproject:fedora:11, p-cpe:/a:fedoraproject:fedora:moodle
Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list
Patch Publication Date: 12/11/2009
Vulnerability Publication Date: 12/15/2009