| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2013-0280: Updated moodle package fixes multiple security vulnerabilities |
| Date: |
| Thu, 19 Sep 2013 11:33:32 +0200 |
| Message-ID: |
| <20130919093332.437CA5B09B@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2013-0280 - Updated moodle package fixes multiple security vulnerabilities
Publication date: 19 Sep 2013
URL: http://advisories.mageia.org/MGASA-2013-0280.html
Type: security
Affected Mageia releases: 3
CVE: CVE-2013-4313,
CVE-2013-4341
Description:
Updated moodle package fixes security vulnerabilities:
Null characters were allowed in query strings in Moodle before 2.4.6, which
caused sql statements to terminate and fail, potentially allowing sql
injection in Moodle's SQL Server driver (CVE-2013-4313).
Links to external blogs were not being adequately cleaned in Moodle before
2.4.6, potentially allowing for XSS attacks (CVE-2013-4341).
References:
- https://moodle.org/mod/forum/discuss.php?d=238396
- https://moodle.org/mod/forum/discuss.php?d=238399
- http://docs.moodle.org/dev/Moodle_2.4.6_release_notes
- https://moodle.org/mod/forum/discuss.php?d=237413
- https://bugs.mageia.org/show_bug.cgi?id=11212
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4313
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4341
SRPMS:
- 3/core/moodle-2.4.6-1.mga3
(
Log in to post comments)