Tcl code injection security exposure

Tcl code injection security exposure Security Advisory Security Advisory Description Certain coding practices may allow an attacker to inject arbitrary Tool Command Language (Tcl) commands, which ... More info: https://support.f5.com/csp/article/K15650046

MSA-19-0012: Private files uploaded via incoming mail processing could bypass quota restrictions

by Michael Hawkins. The size of users private file uploads via email were not correctly checked, so their quota allowance could be exceeded.Severity/Risk:MinorVersions affected:3.6 to 3.6.3, 3.5 to 3.5.5, 3.4 to 3.4.8, 3.1 to 3.1.17 and earlier unsupported versionsVersions fixed:3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18Reported by:Guillermo Leon Alvarez SalamancaWorkaround:Disable the "Email to Private files" message handler until the fix is applied. This is disabled by default in More info: https://moodle.org/mod/forum/discuss.php?d=386524&parent=1557998
Translate »