MGASA-2014-0379
Dashboard / Vulnerabilities / MGASA-2014-0379
Summary: Updated moodle packages fix security vulnerbilities
Details: Updated moodle packages fix security vulnerabilities: In Moodle before 2.6.5, users who had not yet posted the required answer in a Q&A forum in order to access past posts were able to see the name of the last person who had posted, as other authors are visible in /mod/forum/view.php before the student has posted their own answer (CVE-2014-3617).
References: https://advisories.mageia.org/MGASA-2014-0379.html, https://bugs.mageia.org/show_bug.cgi?id=14081, https://moodle.org/mod/forum/discuss.php?d=269590, https://moodle.org/mod/forum/discuss.php?d=269591, https://moodle.org/mod/forum/discuss.php?d=269089, https://docs.moodle.org/dev/Moodle_2.6.5_release_notes
Affected packages
Package
Name: moodle
Purl: pkg:rpm/mageia/moodle?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
