Red Hat Bugzilla – Bug 1052000
CVE-2014-0009 moodle: group constraint checking issue for loginas (MSA-14-0002)
Last modified: 2015-08-22 11:37:32 EDT
Itamar Tzadok found an issue in the group constraint checking for loginas. In some cases if a user had loginas privileges but not the site:accessallgroups capability, they could use this flaw to log in as a user not in their group. This issue affected Moodle versions 2.6, 2.5 to 2.5.4, 2.4 to 2.4.7, 2.3 to 2.3.10 and earlier unsupported versions. It has been fixed in 2.6.1, 2.5.4, 2.4.8 and 2.3.11.
I have not checked if versions 1.9.19 in EPEL 5 is affected or not.
According to the Moodle documentation, loginas cannot be used to log in as an administrator:
Created moodle tracking bugs for this issue:
Affects: fedora-all [bug 1055388]
Affects: epel-all [bug 1055390]