Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 29: 2019-d8ec88b21e Moderate: User Privacy Fixes for Moodle

fedora
Calendar Grey January 31, 2019
Dist Fedora Esm H88
The 2020 Moodle security patch 5a1f67c9c0 resolves various vulnerabilities affecting CentOS 7, ensuring enhanced data protection for user information.
Multiple CVE fixes.

Summary

Moodle is a course management system (CMS) - a free, Open Source software

package designed using sound pedagogical principles, to help educators create

effective online learning communities.

Multiple CVE fixes.

* Tue Jan 22 2019 Gwyn Ciesla - 3.5.4-1

- 3.5.4

* Wed Nov 21 2018 Gwyn Ciesla - 3.5.3-1

- 3.5.3

* Tue Oct 30 2018 Gwyn Ciesla - 3.5.2-2

- Fix URL, drop php-Smarty.

[ 1 ] Bug #1668074 - CVE-2019-3810 moodle: User full name is not escaped in the un-linked userpix page (MSA-19-0003) [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1668074

[ 2 ] Bug #1668068 - CVE-2019-3809 moodle: Blind SSRF Risk in /badges/mybackpack.php (MSA-19-0002) [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1668068

[ 3 ] Bug #1668066 - CVE-2019-3808 moodle: Manage groups capability is missing XSS risk flag (MSA-19-0001) [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1668066

[ 4 ] Bug #1668065 - CVE-2019-3808 moodle: Manage groups capability is missing XSS risk flag (MSA-19-0001) [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1668065

su -c 'dnf upgrade --advisory FEDORA-2019-d8ec88b21e' at the command

line. For more information, refer to the dnf documentation available at

http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 29
Version: 3.5.4
Release: 1.fc29
Summary: A Course Management System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here