Mageia alert MGASA-2016-0029 (moodle)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2016-0029: Updated moodle packages fix security vulnerability | |
| Date: | Wed, 20 Jan 2016 18:54:06 +0100 | |
| Message-ID: | <20160120175406.BDE4021E830@valstar.mageia.org> |
MGASA-2016-0029 - Updated moodle packages fix security vulnerability Publication date: 20 Jan 2016 URL: http://advisories.mageia.org/MGASA-2016-0029.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-0724, CVE-2016-0725 Description: In Moodle before 2.8.10, web services core_enrol_get_course_enrolment_methods and enrol_self_get_instance_info did not check user permission to access hidden courses (CVE-2016-0724). In Moodle before 2.8.10, search string in course management interface was not escaped when being output creating potential for XSS attack (CVE-2016-0725). References: - https://bugs.mageia.org/show_bug.cgi?id=17537 - https://moodle.org/mod/forum/discuss.php?d=326205 - https://moodle.org/mod/forum/discuss.php?d=326206 - https://docs.moodle.org/dev/Moodle_2.8.10_release_notes - https://moodle.org/mod/forum/discuss.php?d=325820 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0724 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0725 SRPMS: - 5/core/moodle-2.8.10-1.mga5
