Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 9: 2020-1642 Moderate: Moodle Multiple Security Fixes

fedora
Calendar Grey February 12, 2009
Dist Fedora Esm H88
Numerous updates for security vulnerabilities in the Moodle learning platform on Fedora 9 strengthen overall system security.
Multiple security fixes.

Summary

Moodle is a course management system (CMS) - a free, Open Source software

package designed using sound pedagogical principles, to help educators create

effective online learning communities.

Multiple security fixes.

* Tue Feb 10 2009 Jon Ciesla - 1.9.4-1

- Update to 1.9.4 to fix CVE-2009-0499,0500,0501,0502.

* Tue Jan 27 2009 Jon Ciesla - 1.9.3-6

- Dropped and symlinked to khmeros-base-fonts.

* Tue Jan 20 2009 Jon Ciesla - 1.9.3-5

- Dropped and symlinked illegal sm and to fonts.

- Symlinking to FreeSans.

- Drop spell-check-logic.cgi, CVE-2008-5153, per upstream, BZ 472117, 472119, 472120.

* Wed Dec 17 2008 Jon Ciesla - 1.9.3-4

- Texed fix, BZ 476709.

* Fri Nov 7 2008 Jon Ciesla - 1.9.3-3

- Moved to weekly downloaded 11/7/08 to fix Snoopy CVE-2008-4796.

* Fri Oct 31 2008 Jon Ciesla - 1.9.3-2

- Fix for BZ 468929, overactive cron job.

* Wed Oct 22 2008 Jon Ciesla - 1.9.3-1

- Updated to 1.9.3.

- Updated language packs to 22 Oct 2008 versions.

* Wed Aug 6 2008 Jon Ciesla - 1.9.2-2

- Remove bundled adodb, use system php-adodb. BZ 457886.

- Remove bundled magpie, use system php-magpierss. BZ 457886.

* Wed Aug 6 2008 Jon Ciesla - 1.9.2-1

- Updated to 1.9.2.

- Remove bundled Smarty, use system php-Smarty. BZ 457886.

- Updated language packs to 06 Aug 2008 versions.

* Mon Jun 23 2008 Jon Ciesla - 1.9.1-2

- Add php Requires, BZ 452341.

* Thu May 22 2008 Jon Ciesla - 1.9.1-1

- Update to 1.9.1.

- Updated language packs to 22 May 2008 versions.

- Added Welsh, Uzbek support.

- Added php-xmlrpc Requires.

[ 1 ] Bug #484916 - CVE-2009-0499 moodle: CSRF vuln in forum code

https://bugzilla.redhat.com/show_bug.cgi?id=484916

[ 2 ] Bug #484922 - CVE-2009-0500 moodle: XSS vuln due to missing input validation in logs

https://bugzilla.redhat.com/show_bug.cgi?id=484922

[ 3 ] Bug #484924 - CVE-2009-0502 moodle: XSS vuln in HTML blocks

https://bugzilla.redhat.com/show_bug.cgi?id=484924

[ 4 ] Bug #484923 - CVE-2009-0501 moodle: calendar export may allow brute force attacks

https://bugzilla.redhat.com/show_bug.cgi?id=484923

su -c 'yum update moodle' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 9
Version: 1.9.4
Release: 1.fc9
Summary: A Course Management System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here