[SECURITY] [DSA 1761-1] New moodle packages fix file disclosure

Debian Security Advisory DSA-1761-1
http://www.debian.org/security/                                 Nico Golde
April 3rd, 2009
Package        : moodle
Vulnerability  : missing input sanitization
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2009-1171
Debian Bug     : 522116

Christian J. Eibl discovered that the TeX filter of Moodle, a web-based
course management system, doesn't check user input for certain TeX commands
which allows an attacker to include and display the content of arbitrary system

Note that this doesn't affect installations that only use the mimetex

For the oldstable distribution (etch), this problem has been fixed in
version 1.6.3-2+etch3.

For the stable distribution (lenny), this problem has been fixed in
version 1.8.2.dfsg-3+lenny2.

For the testing distribution (squeeze), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 1.8.2.dfsg-5.

We recommend that you upgrade your moodle packages.

Upgrade instructions
Debian GNU/Linux 4.0 alias etch
Debian (oldstable)
Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

    Source archives:
    Size/MD5 checksum:    27511 974a829196380027ac19e82ecd4a6e82

Architecture independent packages:

    Size/MD5 checksum:  6583190 7d5c0c3103021541b308f54bfc2e2d55

Debian GNU/Linux 5.0 alias lenny
Debian (stable)
Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

    Source archives:
    Size/MD5 checksum:     1390 e7a4b2fe58e3b53f6c4bf6327a007509

Architecture independent packages:

    Size/MD5 checksum:  8713446 6a9345748982edab6a52047abe6779f6

  These files will probably be moved into the stable distribution on
  its next update.

Reply to: