PT-2020-16139 · Moodle+1 · Moodle+1

Ivan Novichkov

·

Published

2020-10-15

·

Updated

2024-03-06

·

CVE-2020-25630

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Moodle versions 3.5 to 3.5.13 Moodle versions 3.7 to 3.7.7 Moodle versions 3.8 to 3.8.4 Moodle versions 3.9 to 3.9.1
Description A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk.
Recommendations For versions 3.5 to 3.5.13, update to version 3.5.14 to resolve the issue. For versions 3.7 to 3.7.7, update to version 3.7.8 to resolve the issue. For versions 3.8 to 3.8.4, update to version 3.8.5 to resolve the issue. For versions 3.9 to 3.9.1, update to version 3.9.2 to resolve the issue.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3059
ALT-PU-2020-3289
ALT-PU-2022-1641
BIT-MOODLE-2020-25630
CVE-2020-25630
GHSA-66XP-28CQ-MRF2

Affected Products

Alt Linux
Moodle