MGASA-2014-0379

Source
https://advisories.mageia.org/MGASA-2014-0379.html
Import Source
https://advisories.mageia.org/MGASA-2014-0379.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0379
Upstream
  • CVE-2014-3617
Published
2014-09-15T10:36:30Z
Modified
2026-04-16T06:25:35.512533626Z
Summary
Updated moodle packages fix security vulnerbilities
Details

Updated moodle packages fix security vulnerabilities:

In Moodle before 2.6.5, users who had not yet posted the required answer in a Q&A forum in order to access past posts were able to see the name of the last person who had posted, as other authors are visible in /mod/forum/view.php before the student has posted their own answer (CVE-2014-3617).

References
Credits

Affected packages

Mageia:3 / moodle

Package

Name
moodle
Purl
pkg:rpm/mageia/moodle?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.5-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0379.json"

Mageia:4 / moodle

Package

Name
moodle
Purl
pkg:rpm/mageia/moodle?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.5-1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0379.json"