LWN.net Logo

moodle: arbitrary file access

Package(s):moodle CVE #(s):CVE-2009-1171
Created:April 2, 2009 Updated:June 25, 2009
Description: moodle can allow access to arbitrary files. From the National vulnerability database: The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.
Alerts:
Ubuntu USN-791-2 2009-06-24
Ubuntu USN-791-1 2009-06-24
SuSE SUSE-SR:2009:009 2009-04-21
Debian DSA-1761-1 2009-04-03
Fedora FEDORA-2009-3280 2009-04-02
Fedora FEDORA-2009-3283 2009-04-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds