MGASA-2014-0387
Dashboard / Vulnerabilities / MGASA-2014-0387
Summary: Updated php-pear-CAS packages fix CVE-2014-4172
Details: Updated php-pear-CAS packages fix security vulnerabilities: A flaw in php-pear-CAS before 1.3.3, utilized by Moodle, has been found which could potentially allow unauthorised access and privilege escalation (CVE-2014-4172).
References: https://advisories.mageia.org/MGASA-2014-0387.html, https://bugs.mageia.org/show_bug.cgi?id=14139
Affected packages
Package
Name: php-pear-CAS
Purl: pkg:rpm/mageia/php-pear-CAS?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.3.3-1.mga3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
