An information disclosure flaw was found in the way XML RPC interface of web services of Moodle, a course management system, performed loading of certain XML files. A remote attacker (valid Moodle user) could use this flaw to obtain sensitive information (certain server files). References: [1] http://www.openwall.com/lists/oss-security/2013/03/25/2 Relevant upstream patch: [2] http://git.moodle.org/gw?p=moodle.git;a=commit;h=dfe203c12e4fdb4696b59928f90bb06cb1d8b9a7
This issue affects the versions of the moodle package, as shipped with Fedora release of 18, 17, and Fedora EPEL-6. Please schedule an update. -- This issue did NOT affect the version of the moodle package, as shipped with Fedora EPEL-5.
Created moodle tracking bugs for this issue Affects: fedora-18 [bug 927264]
Created moodle tracking bugs for this issue Affects: fedora-17 [bug 927267]
Created moodle tracking bugs for this issue Affects: epel-6 [bug 927273]