Re: Please, accept Moodle 1.4.4-3 in Sarge

2005-05-30 Thread Steve Langasek
On Mon, May 30, 2005 at 10:42:07PM +0200, Isaac Clerencia wrote: > Moodle 1.4.4 has an important security bug in a "hidden" utility. > The file delete.php is an easy way to completely delete your Moodle data, but > *as it is now* it can be used by a non-privileged attacker. > The easiest propose

Please, accept Moodle 1.4.4-3 in Sarge

2005-05-30 Thread Isaac Clerencia
Moodle 1.4.4 has an important security bug in a "hidden" utility. The file delete.php is an easy way to completely delete your Moodle data, but *as it is now* it can be used by a non-privileged attacker. The easiest proposed fix is to just don't ship the file with Moodle, as it's a "hidden", no