Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 9: 3283 Critical: Moodle TeX Filter File Disclosure Threat

fedora
Calendar Grey April 2, 2009
Dist Fedora Esm H88
Moodle 1.9.4-6.fc9 addresses a vulnerability related to file exposure through the TeX filter. Fedora users should apply this update promptly. More information available within.
CVE-2009-1171: The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via...

Summary

Moodle is a course management system (CMS) - a free, Open Source software

package designed using sound pedagogical principles, to help educators create

effective online learning communities.

CVE-2009-1171: The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+,

1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read

arbitrary files via an input command in a "$$" sequence, which causes LaTeX to

include the contents of the file. Upstream bug and CVS commit:

https://id.atlassian.com/login?continue=https%3A%2F%2Fid.atlassian.com%2Fjoin%2Fuser-access%3Fresource%3Dari%253Acloud%253Ajira%253A%253Asite%252Fdb26294c-09fa-4e4e-bebe-d7410e9e2a67%26continue%3Dhttps%253A%252F%252Fmoodle.atlassian.net%252Fjira&application=jira

;r2=1.18.4.5

References:

Upstream further reported that the above patch is not sufficient and following

change should be used instead: For >=1.9.0: For

1.6.* - 1.8.*: ;a=commitdiff;h=cc9

bf1486e7ea9e8cda1e4522b96e07245459a0d

* Wed Apr 1 2009 Jon Ciesla - 1.9.4-6

- Patch for CVE-2009-1171, BZ 493109.

* Tue Mar 24 2009 Jon Ciesla - 1.9.4-5

- Update for freefont->gnu-free-fonts change.

* Thu Feb 26 2009 Jon Ciesla - 1.9.4-4

- Fix for symlink dir replacement.

* Mon Feb 23 2009 Jon Ciesla - 1.9.4-2

- Putting back bundled MagpieRSS due to incompatibility, BZ 486777.

- Corrected moodle-cron.

* Tue Feb 10 2009 Jon Ciesla - 1.9.4-1

- Update to 1.9.4 to fix CVE-2009-0499,0500,0501,0502.

* Tue Jan 27 2009 Jon Ciesla - 1.9.3-6

- Dropped and symlinked to khmeros-base-fonts.

* Tue Jan 20 2009 Jon Ciesla - 1.9.3-5

- Dropped and symlinked illegal sm and to fonts.

- Symlinking to FreeSans.

- Drop spell-check-logic.cgi, CVE-2008-5153, per upstream, BZ 472117, 472119, 472120.

* Wed Dec 17 2008 Jon Ciesla - 1.9.3-4

- Texed fix, BZ 476709.

* Fri Nov 7 2008 Jon Ciesla - 1.9.3-3

- Moved to weekly downloaded 11/7/08 to fix Snoopy CVE-2008-4796.

* Fri Oct 31 2008 Jon Ciesla - 1.9.3-2

- Fix for BZ 468929, overactive cron job.

* Wed Oct 22 2008 Jon Ciesla - 1.9.3-1

- Updated to 1.9.3.

- Updated language packs to 22 Oct 2008 versions.

* Wed Aug 6 2008 Jon Ciesla - 1.9.2-2

- Remove bundled adodb, use system php-adodb. BZ 457886.

- Remove bundled magpie, use system php-magpierss. BZ 457886.

* Wed Aug 6 2008 Jon Ciesla - 1.9.2-1

- Updated to 1.9.2.

- Remove bundled Smarty, use system php-Smarty. BZ 457886.

- Updated language packs to 06 Aug 2008 versions.

* Mon Jun 23 2008 Jon Ciesla - 1.9.1-2

- Add php Requires, BZ 452341.

* Thu May 22 2008 Jon Ciesla - 1.9.1-1

- Update to 1.9.1.

- Updated language packs to 22 May 2008 versions.

- Added Welsh, Uzbek support.

- Added php-xmlrpc Requires.

[ 1 ] Bug #493109 - CVE-2009-1171 moodle: file disclosure flaw in TeX filter

https://bugzilla.redhat.com/show_bug.cgi?id=493109

su -c 'yum update moodle' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 9
Version: 1.9.4
Release: 6.fc9
Summary: A Course Management System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here