<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Datacenterperu &#187; actualizar</title>
	<atom:link href="http://www.datacenterperu.com/beta/tag/actualizar/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.datacenterperu.com/beta</link>
	<description></description>
	<lastBuildDate>Wed, 31 Mar 2010 15:45:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<copyright>Copyright &#xA9; Datacenterperu 2010 </copyright>
	<managingEditor>info@datacenterperu.com (Datacenterperu)</managingEditor>
	<webMaster>info@datacenterperu.com (Datacenterperu)</webMaster>
	<image>
		<url>http://datacenterperu.com/beta/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
		<title>Datacenterperu</title>
		<link>http://www.datacenterperu.com/beta</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary></itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Society &#38; Culture" />
	<itunes:author>Datacenterperu</itunes:author>
	<itunes:owner>
		<itunes:name>Datacenterperu</itunes:name>
		<itunes:email>info@datacenterperu.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://datacenterperu.com/beta/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<item>
		<title>Liberadas las versiones de seguridad Moodle 1.9.3, Moodle 1.8.7, Moodle 1.7.6 y Moodle 1.6.8</title>
		<link>http://www.datacenterperu.com/beta/blog/liberadas-las-versiones-de-seguridad-moodle-193-moodle-187-moodle-176-y-moodle-168/</link>
		<comments>http://www.datacenterperu.com/beta/blog/liberadas-las-versiones-de-seguridad-moodle-193-moodle-187-moodle-176-y-moodle-168/#comments</comments>
		<pubDate>Tue, 30 Dec 2008 04:00:54 +0000</pubDate>
		<dc:creator>Datacenterperu</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Moodle]]></category>
		<category><![CDATA[Seguridad Informatica]]></category>
		<category><![CDATA[actualizar]]></category>
		<category><![CDATA[seguridad]]></category>

		<guid isPermaLink="false">http://datacenterperu.com/beta/?p=182</guid>
		<description><![CDATA[Se han publicado nuevas versiones de Moodle que solucionan problemas de seguridad de esta aula virtual y es por tanto más que recomendable actualizar su sitio Web Moodle. Recuerde que el paso de una versión inferior a una superior puede necesitar modificaciones en las plantillas. Estas modificaciones deben presupuestarse aparte (Ejemplo de versiones 1.6.x a [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-183" title="moodle" src="http://datacenterperu.com/beta/wp-content/uploads/2008/12/moodle.png" alt="moodle" width="264" height="65" /></p>
<p>Se han publicado nuevas versiones de Moodle que solucionan problemas de seguridad de esta aula virtual y es por tanto más que recomendable actualizar su sitio Web Moodle.</p>
<p>Recuerde que el paso de una versión inferior a una superior puede necesitar modificaciones en las plantillas. Estas modificaciones deben presupuestarse aparte (Ejemplo de versiones 1.6.x a 1.8.x y/o 1.9.x).</p>
<p>De la versión 1.9.2 a la 1.9.3 no existen variaciones en el diseño de la plantilla.</p>
<p><span id="more-182"></span>Información en inglés:</p>
<p>==MSA-08-0019==</p>
<p>Topic: customised PhpMyAdmin upgraded to 2.11.9.2<br />
Severity: MAJOR<br />
Versions affected: all<br />
Reported by: upstream PMASA-2008-8<br />
Issue no.: MDL-16623<br />
Solution: Install latest package from</p>
<p>http://moodle.org/mod/data/view.php?d=13&#038;rid=448</p>
<p>Description:<br />
see http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-8</p>
<p>==MSA-08-0020==</p>
<p>Topic: quiz/questions capabilities lack some risk flags in<br />
access.php files<br />
Severity: MINOR<br />
Versions affected: &lt; 1.7.6, &lt; 1.8.7, &lt; 1.9.3<br />
Reported by: internal code review<br />
Issue no.: MDL-15819<br />
Solution: update to latest releases</p>
<p>Description:<br />
We have discovered during code review that some quiz<br />
and questions related capabilities lack proper definition<br />
of associated risks. Administrators should update sites or<br />
at least review the changes in risk definitions in all quiz<br />
and question related capabilities.</p>
<p>==MSA-08-0021==</p>
<p>Topic: design deficiency combined with incorrect use of<br />
format_string() allowing XSS<br />
Severity: HIGH<br />
Versions affected: &lt; 1.6.8, &lt; 1.7.6, &lt; 1.8.7, &lt; 1.9.3<br />
Reported by: Lars Vogdt<br />
Issue no.: MDL-15823<br />
Solution: Update to latest releases or patch format_string() function<br />
1.6.x http://cvs.moodle.org/moodle/lib/weblib.php?r1=1.581.4.12&amp;r2=1.581.4.13<br />
1.7.x http://cvs.moodle.org/moodle/lib/weblib.php?r1=1.674.2.35&amp;r2=1.674.2.36<br />
1.8.x</p>
<p>http://cvs.moodle.org/moodle/lib/weblib.php?view=log&#038;pathrev=MOODLE_18_STABLE</p>
<p>1.9.x http://cvs.moodle.org/moodle/lib/weblib.php?r1=1.970.2.103&amp;r2=1.970.2.104</p>
<p>Description:<br />
Lars Vogdt reported a Cross Site Scripting (XSS) problem in<br />
one script, during the evaluation we have realised that several<br />
other places might be affected too. The problem was caused by<br />
combination of incorrect use of format_string() and previous<br />
design of this function. We have decided to prevent this and<br />
any similar problems in future by adding more sanitisation into<br />
format_string().</p>
<p>==MSA-08-0022==</p>
<p>Topic: XSS through Wiki page titles<br />
Severity: HIGH<br />
Versions affected: &lt; 1.6.8, &lt; 1.7.6, &lt; 1.8.7, &lt; 1.9.3<br />
Reported by: Mike Churchward<br />
Issue no.: MDL-15896<br />
Solution: update to latest releases</p>
<p>Description:<br />
Wiki page names were not sanitised on output, allowing<br />
for potential cross site scripting (XSS) issues.</p>
<p>==MSA-08-0023==</p>
<p>Topic: CSRF in messaging setting<br />
Severity: MAJOR<br />
Versions affected: &lt; 1.6.8, &lt; 1.7.6, &lt; 1.8.7, &lt; 1.9.3<br />
Reported by: internal code review<br />
Issue no.: MDL-16688<br />
Solution: update to latest releases</p>
<p>Description:<br />
The messaging settings page was exposed to a CSRF<br />
vulnerability because it wasn&#8217;t protected by the<br />
sesskey mechanism.</p>
<p>==MSA-08-0024==</p>
<p>Topic: Overriding of frozen values in Moodle forms<br />
Severity: MINOR<br />
Versions affected: &lt; 1.8.7, &lt; 1.9.3<br />
Reported by: Ashley Holman<br />
Issue no.: MDL-16839<br />
Solution: update to latest releases</p>
<p>Description:<br />
Anshley Holman reported that it is possible to side<br />
step user profile locking mechanism. The cause of<br />
this is in our quickforms integration, unfortunately<br />
it can not be fixed without potential regressions.<br />
We have decided to work around this problem by<br />
using setConstant() together with hardFreeze().<br />
Please update your code in a similar way if required.<br />
The problem will be better resolved in 2.0.</p>
<p>==MSA-08-0025==</p>
<p>Topic: SQL injection in tags code<br />
Severity: HIGH<br />
Versions affected: 1.9.0, 1.9.1, 1.9.2<br />
Reported by: D P<br />
Issue no.: MDL-16585<br />
Solution: update to latest release</p>
<p>Description:<br />
SQL injection problem was reported in tag related code.<br />
Please update your site or disable tags feature.</p>
<p>==MSA-08-0026==</p>
<p>Topic: customised HTML Purifier upgraded to 2.1.5<br />
Severity: MINOR<br />
Versions affected: 1.9.0, 1.9.1, 1.9.2<br />
Reported by: upstream<br />
Issue no.: MDL-16667<br />
Solution: upgrade to latest release or use standard kses text cleaning engine</p>
<p>Description:<br />
see http://htmlpurifier.org/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.datacenterperu.com/beta/blog/liberadas-las-versiones-de-seguridad-moodle-193-moodle-187-moodle-176-y-moodle-168/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

