Multiple CVE fixes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ddb5f7c0a3 2024-12-27 01:20:43.467440+00:00 -------------------------------------------------------------------------------- Name : moodle Product : Fedora 41 Version : 4.4.5 Release : 1.fc41 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. -------------------------------------------------------------------------------- Update Information: Multiple CVE fixes. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 17 2024 Gwyn Ciesla - 4.4.5-1 - 4.4.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2332796 - CVE-2024-55648 moodle: Potential denial of service risk due to guest sessions' longer timeout period [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332796 [ 2 ] Bug #2332812 - CVE-2024-55647 moodle: Reflected XSS in question bank filter [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332812 [ 3 ] Bug #2332814 - CVE-2024-55646 moodle: Database activity issue in separate groups mode, for users not in a group [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332814 [ 4 ] Bug #2332824 - CVE-2024-55645 moodle: Email change confirmation token available via preference [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332824 [ 5 ] Bug #2332826 - CVE-2024-55644 moodle: Tag index page displays other users tagged with the selected tag [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332826 [ 6 ] Bug #2332828 - CVE-2024-55643 moodle: Unprotected access to sensitive information via learning plan webservice [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332828 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ddb5f7c0a3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes for multiple CVEs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-cb7084ae1c 2022-12-07 01:42:32.810680 --------------------------------------------------------------------------------Name : moodle Product : Fedora 35 Version : 3.11.11 Release : 1.fc35 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Fixes for multiple CVEs --------------------------------------------------------------------------------ChangeLog: * Mon Nov 28 2022 Gwyn Ciesla - 3.11.11-1 - 3.11.11 --------------------------------------------------------------------------------References: [ 1 ] Bug #2144705 - CVE-2021-23414 CVE-2022-45149 CVE-2022-45150 CVE-2022-45151 CVE-2022-45152 moodle: various flaws [fedora-35] https://bugzilla.redhat.com/show_bug.cgi?id=2144705 [ 2 ] Bug #2144706 - CVE-2021-23414 CVE-2022-45149 CVE-2022-45150 CVE-2022-45151 CVE-2022-45152 moodle: various flaws [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2144706 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-cb7084ae1c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Latest update.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-1c77803b43 2022-09-21 01:11:30.390293 --------------------------------------------------------------------------------Name : moodle Product : Fedora 36 Version : 3.11.10 Release : 1.fc36 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Latest update. --------------------------------------------------------------------------------ChangeLog: * Mon Sep 12 2022 Gwyn Ciesla - 3.11.10-1 - 3.11.10 --------------------------------------------------------------------------------References: [ 1 ] Bug #2126857 - CVE-2021-36568 www-apps/moodle: XSS via crafted topic fields https://bugzilla.redhat.com/show_bug.cgi?id=2126857 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-1c77803b43' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fixes for multiple CVEs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-431b232659 2021-03-23 01:31:48.604577 --------------------------------------------------------------------------------Name : moodle Product : Fedora 33 Version : 3.9.5 Release : 1.fc33 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Fixes for multiple CVEs --------------------------------------------------------------------------------ChangeLog: * Mon Mar 15 2021 Gwyn Ciesla - 3.9.5-1 - 3.9.5 --------------------------------------------------------------------------------References: [ 1 ] Bug #1939035 - CVE-2021-20279 moodle: Stored XSS via ID number user profile field [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939035 [ 2 ] Bug #1939039 - CVE-2021-20280 moodle: Stored XSS and blind SSRF possible via feedback answer text [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939039 [ 3 ] Bug #1939047 - CVE-2021-20281 moodle: User full name disclosure within online users block [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939047 [ 4 ] Bug #1939049 - CVE-2021-20282 moodle: Bypass email verification secret when confirming account registration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939049 [ 5 ] Bug #1939053 - CVE-2021-20283 moodle: Fetching a user's enrolled courses via web services did not check profile access in each course [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1939053 --------------------------------------------------------------------------------This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-431b232659' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
3.1.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-536d043512 2016-11-19 18:59:18.606414 -------------------------------------------------------------------------------- Name : moodle Product : Fedora 25 Version : 3.1.3 Release : 1.fc25 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. -------------------------------------------------------------------------------- Update Information: 3.1.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1392336 - CVE-2016-9186 CVE-2016-9187 CVE-2016-9188 moodle: Multiple vulnerabilities in 3.1.2 and before [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1392336 [ 2 ] Bug #1392335 - CVE-2016-9186 CVE-2016-9187 CVE-2016-9188 moodle: Multiple vulnerabilities in 3.1.2 and before [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1392335 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade moodle' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
moodle-2.8.7-1.fc22 - Latest upstream release.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14988 2015-09-15 17:10:28.689196 -------------------------------------------------------------------------------- Name : moodle Product : Fedora 22 Version : 2.8.7 Release : 1.fc22 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. -------------------------------------------------------------------------------- Update Information: moodle-2.8.7-1.fc22 - Latest upstream release. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1222602 - CVE-2015-3181 CVE-2015-3180 CVE-2015-3178 CVE-2015-3179 CVE-2015-3176 CVE-2015-3177 CVE-2015-3174 CVE-2015-3175 moodle: several flaws fixed in 2.9, 2.8.6, 2.7.8, 2.6.11 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1222602 [ 2 ] Bug #1242777 - CVE-2015-3273 CVE-2015-3272 CVE-2015-3275 CVE-2015-3274 moodle: multiple flaws fixed in 2.9.1, 2.8.7, and 2.7.9 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1242777 [ 3 ] Bug #1221278 - moodle: multiple unspecified flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1221278 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update moodle' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announcemailing list
Get the latest Linux and open source security news straight to your inbox.