MGASA-2013-0356
Dashboard / Vulnerabilities / MGASA-2013-0356
MGASA-2013-0356
Summary: Updated moodle package fixes security vulnerabilities
Details: Some files were being delivered with incorrect headers in Moodle before 2.4.7, meaning they could be cached downstream (CVE-2013-4522). Cross-site scripting in Moodle before 2.4.7 due to JavaScript in messages being executed on some pages (CVE-2013-4523). The file system repository in Moodle before 2.4.7 was allowing access to files beyond the Moodle file area (CVE-2013-4524). Cross-site scripting in Moodle before 2.4. due to JavaScript in question answers being executed on the Quiz Results page (CVE-2013-4525).
References: https://advisories.mageia.org/MGASA-2013-0356.html, https://bugs.mageia.org/show_bug.cgi?id=11671, https://moodle.org/mod/forum/discuss.php?d=244479, https://moodle.org/mod/forum/discuss.php?d=244480, https://moodle.org/mod/forum/discuss.php?d=244481, https://moodle.org/mod/forum/discuss.php?d=244482, http://docs.moodle.org/dev/Moodle_2.4.7_release_notes, https://moodle.org/mod/forum/discuss.php?d=243213
Affected packages
Package
Name: moodle
Purl: pkg:rpm/mageia/moodle?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
