Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 10: 2009-3280 Moderate: Moodle TeX Filter File Access Risk

fedora
Calendar Grey April 2, 2009
Dist Fedora Esm H88
Moodle patch resolves critical file leakage in TeX filter on Fedora 10. Urgent update advised for enhanced security.
CVE-2009-1171: The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via...

Summary

Moodle is a course management system (CMS) - a free, Open Source software

package designed using sound pedagogical principles, to help educators create

effective online learning communities.

CVE-2009-1171: The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+,

1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read

arbitrary files via an input command in a "$$" sequence, which causes LaTeX to

include the contents of the file. Upstream bug and CVS commit:

https://id.atlassian.com/login?continue=https%3A%2F%2Fid.atlassian.com%2Fjoin%2Fuser-access%3Fresource%3Dari%253Acloud%253Ajira%253A%253Asite%252Fdb26294c-09fa-4e4e-bebe-d7410e9e2a67%26continue%3Dhttps%253A%252F%252Fmoodle.atlassian.net%252Fjira&application=jira

;r2=1.18.4.5

References:

Upstream further reported that the above patch is not sufficient and following

change should be used instead: For >=1.9.0: For

1.6.* - 1.8.*: ;a=commitdiff;h=cc9

bf1486e7ea9e8cda1e4522b96e07245459a0d

* Wed Apr 1 2009 Jon Ciesla - 1.9.4-6

- Patch for CVE-2009-1171, BZ 493109.

* Tue Mar 24 2009 Jon Ciesla - 1.9.4-5

- Update for freefont->gnu-free-fonts change.

* Thu Feb 26 2009 Jon Ciesla - 1.9.4-4

- Fix for symlink dir replacement.

* Mon Feb 23 2009 Jon Ciesla - 1.9.4-2

- Putting back bundled MagpieRSS due to incompatibility, BZ 486777.

- Corrected moodle-cron.

* Tue Feb 10 2009 Jon Ciesla - 1.9.4-1

- Update to 1.9.4 to fix CVE-2009-0499,0500,0501,0502.

* Tue Jan 27 2009 Jon Ciesla - 1.9.3-6

- Dropped and symlinked to khmeros-base-fonts.

* Tue Jan 20 2009 Jon Ciesla - 1.9.3-5

- Dropped and symlinked illegal sm and to fonts.

- Symlinking to FreeSans.

- Drop spell-check-logic.cgi, CVE-2008-5153, per upstream, BZ 472117, 472119, 472120.

* Wed Dec 17 2008 Jon Ciesla - 1.9.3-4

- Texed fix, BZ 476709.

* Fri Nov 7 2008 Jon Ciesla - 1.9.3-3

- Moved to weekly downloaded 11/7/08 to fix Snoopy CVE-2008-4796.

* Fri Oct 31 2008 Jon Ciesla - 1.9.3-2

- Fix for BZ 468929, overactive cron job.

[ 1 ] Bug #493109 - CVE-2009-1171 moodle: file disclosure flaw in TeX filter

https://bugzilla.redhat.com/show_bug.cgi?id=493109

su -c 'yum update moodle' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 10
Version: 1.9.4
Release: 6.fc10
Summary: A Course Management System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here