Bug 1006673 (CVE-2013-4313, CVE-2013-4341, CVE-2013-5674)
| Summary: | CVE-2013-4313 CVE-2013-4341 CVE-2013-5674 moodle: upstream 2.3.9, 2.4.6, 2.5.2 security fixes | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Ratul Gupta <ratulg> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | gwync |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | moodle 2.3.9, moodle 2.4.6, moodle 2.5.2 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-08-22 15:37:28 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1006678, 1006679 | ||
| Bug Blocks: | 1006684 | ||
|
Description
Ratul Gupta
2013-09-11 05:35:13 UTC
Created moodle tracking bugs for this issue: Affects: fedora-all [bug 1006678] Affects: epel-all [bug 1006679] Common Vulnerabilities and Exposures assigned an identifier CVE-2013-4313 to the following vulnerability: Name: CVE-2013-4313 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4313 Assigned: 20130612 Reference: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-40676 Reference: https://moodle.org/mod/forum/discuss.php?d=238396 Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string. Common Vulnerabilities and Exposures assigned an identifier CVE-2013-4341 to the following vulnerability: Name: CVE-2013-4341 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4341 Assigned: 20130612 Reference: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-41623 Reference: https://moodle.org/mod/forum/discuss.php?d=238399 Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed. Common Vulnerabilities and Exposures assigned an identifier CVE-2013-5674 to the following vulnerability: Name: CVE-2013-5674 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5674 Assigned: 20130902 Reference: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-40924 Reference: https://moodle.org/mod/forum/discuss.php?d=238397 badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter. |