Bug 1077822 (CVE-2013-7341, CVE-2014-0122, CVE-2014-0123, CVE-2014-0124, CVE-2014-0125, CVE-2014-0126, CVE-2014-0127, CVE-2014-0129, CVE-2014-2571, CVE-2014-2572)
| Summary: | CVE-2014-0127 CVE-2014-0122 CVE-2014-0123 CVE-2014-0124 CVE-2014-0125 CVE-2014-0126 CVE-2014-0129 CVE-2013-7341 CVE-2014-2571 CVE-2014-2572 moodle: upstream 2.6.2, 2.5.5, and 2.4.9 fixes | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Martin Prpič <mprpic> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | gwync |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-08-22 15:37:17 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1077823, 1077824 | ||
| Bug Blocks: | |||
|
Description
Martin Prpič
2014-03-18 16:11:23 UTC
Created moodle tracking bugs for this issue: Affects: fedora-all [bug 1077823] Affects: epel-all [bug 1077824] > ======================================================================= > MSA-14-0008: Cross site scripting potential in Flowplayer > > Description: Cross site scripting was possible with Flowplayer > Issue summary: Upgrade flowplayer > Severity/Risk: Minor > Versions affected: 2.6 to 2.6.1, 2.5 to 2.5.4, 2.4 to 2.4.8 and > earlier unsupported versions > Versions fixed: 2.6.2, 2.5.5 and 2.4.9 > Reported by: Andrew Nicols, Simon Coggins > Issue no.: MDL-43344 > CVE identifier: Pending > Changes (master): > http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43344 MITRE assigned CVE-2013-7341 to this issue. > ======================================================================= > MSA-14-0004: Incorrect filtering in Quiz > > Description: Question strings were not being filtered correctly > possibly allowing cross site scripting. > Issue summary: quiz_question_tostring can cause invalid HTML > Severity/Risk: Minor > Versions affected: 2.6 to 2.6.1, 2.5 to 2.5.4, 2.4 to 2.4.8 and > earlier unsupported versions > Versions fixed: 2.6.2, 2.5.5 and 2.4.9 > Reported by: Tim Hunt > Issue no.: MDL-43690, MDL-43846 > CVE identifier: Pending > Changes (master): > http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43690 MITRE assigned CVE-2014-2571 to this issue. > ======================================================================= > MSA-14-0013: Unfiltered data used in Assignment web services > > Description: Assignment web service functions were not correctly > cleaning function parameters allowing alteration > of assignment grade related information. > Issue summary: Review mod/assign external functions > Severity/Risk: Minor > Versions affected: 2.6 to 2.6.1 > Versions fixed: 2.6.2 > Reported by: Eloy Lafuente > Issue no.: MDL-43468 > CVE identifier: Pending > Changes (master): > http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43468 MITRE assigned CVE-2014-2572 to this issue. |