Upstream information
CVE-2009-1171 at MITRE
Description
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.
NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Novell Bugzilla entry:
490087
SUSE Security Advisories:
List of released packages
| Product(s) | Fixed package version(s) | References |
| openSUSE 10.3 | moodle >= 1.8.2-17.14 moodle-af >= 1.8.2-17.14 moodle-ar >= 1.8.2-17.14 moodle-be >= 1.8.2-17.14 moodle-bg >= 1.8.2-17.14 moodle-bs >= 1.8.2-17.14 moodle-ca >= 1.8.2-17.14 moodle-cs >= 1.8.2-17.14 moodle-da >= 1.8.2-17.14 moodle-de >= 1.8.2-17.14 moodle-de_du >= 1.8.2-17.14 moodle-el >= 1.8.2-17.14 moodle-es >= 1.8.2-17.14 moodle-et >= 1.8.2-17.14 moodle-eu >= 1.8.2-17.14 moodle-fa >= 1.8.2-17.14 moodle-fi >= 1.8.2-17.14 moodle-fr >= 1.8.2-17.14 moodle-ga >= 1.8.2-17.14 moodle-gl >= 1.8.2-17.14 moodle-he >= 1.8.2-17.14 moodle-hi >= 1.8.2-17.14 moodle-hr >= 1.8.2-17.14 moodle-hu >= 1.8.2-17.14 moodle-id >= 1.8.2-17.14 moodle-is >= 1.8.2-17.14 moodle-it >= 1.8.2-17.14 moodle-ja >= 1.8.2-17.14 moodle-ka >= 1.8.2-17.14 moodle-km >= 1.8.2-17.14 moodle-kn >= 1.8.2-17.14 moodle-ko >= 1.8.2-17.14 moodle-lt >= 1.8.2-17.14 moodle-lv >= 1.8.2-17.14 moodle-mi_tn >= 1.8.2-17.14 moodle-ms >= 1.8.2-17.14 moodle-nl >= 1.8.2-17.14 moodle-nn >= 1.8.2-17.14 moodle-no >= 1.8.2-17.14 moodle-pl >= 1.8.2-17.14 moodle-pt >= 1.8.2-17.14 moodle-ro >= 1.8.2-17.14 moodle-ru >= 1.8.2-17.14 moodle-sk >= 1.8.2-17.14 moodle-sl >= 1.8.2-17.14 moodle-so >= 1.8.2-17.14 moodle-sq >= 1.8.2-17.14 moodle-sr >= 1.8.2-17.14 moodle-sv >= 1.8.2-17.14 moodle-th >= 1.8.2-17.14 moodle-tl >= 1.8.2-17.14 moodle-tr >= 1.8.2-17.14 moodle-uk >= 1.8.2-17.14 moodle-vi >= 1.8.2-17.14 moodle-zh_cn >= 1.8.2-17.14
| |