Vulnerability Name:

CVE-2009-1171 (CCN-49504)

Assigned:2009-03-27
Published:2009-03-27
Updated:2020-12-01
Summary:The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
3.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-20
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2009-1171

Source: CONFIRM
Type: Exploit
http://cvs.moodle.org/moodle/filter/tex/filter.php?r1=1.18.4.4&r2=1.18.4.5

Source: SUSE
Type: UNKNOWN
SUSE-SR:2009:009

Source: CCN
Type: Moodle Web site
Moodle.org: open-source community-based tools for learning

Source: CCN
Type: SA34517
Moodle TeX Notation Filter Information Disclosure

Source: SECUNIA
Type: UNKNOWN
34517

Source: SECUNIA
Type: UNKNOWN
34557

Source: SECUNIA
Type: UNKNOWN
34600

Source: SECUNIA
Type: UNKNOWN
35570

Source: MISC
Type: UNKNOWN
http://tracker.moodle.org/browse/MDL-18552

Source: CCN
Type: MDLSITE-694
Some errors in apache log files (proxy & latex)

Source: DEBIAN
Type: UNKNOWN
DSA-1761

Source: DEBIAN
Type: DSA-1761
moodle -- missing input sanitization

Source: CCN
Type: OSVDB ID: 52998
Moodle TeX Notation Filter Arbitrary File Access

Source: BUGTRAQ
Type: UNKNOWN
20090327 Moodle: Sensitive File Disclosure

Source: BID
Type: UNKNOWN
34278

Source: CCN
Type: BID-34278
Moodle TeX Filter Remote File Disclosure Vulnerability

Source: CCN
Type: USN-791-1
Moodle vulnerabilities

Source: CCN
Type: USN-791-2
Moodle vulnerability

Source: XF
Type: UNKNOWN
moodle-tex-info-disclosure(49504)

Source: UBUNTU
Type: UNKNOWN
USN-791-2

Source: EXPLOIT-DB
Type: UNKNOWN
8297

Source: FEDORA
Type: UNKNOWN
FEDORA-2009-3280

Source: FEDORA
Type: UNKNOWN
FEDORA-2009-3283

Source: SUSE
Type: SUSE-SR:2009:009
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:moodle:moodle:1.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.8:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.8:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.9.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:moodle:moodle:1.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.9.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.7.6:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.6.8:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.9.4:*:*:*:*:*:*:*
  • OR cpe:/a:moodle:moodle:1.8.8:*:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20091171
    V
    CVE-2009-1171
    2015-11-16
    oval:org.mitre.oval:def:13316
    P
    USN-791-2 -- moodle vulnerability
    2014-07-07
    oval:org.mitre.oval:def:13687
    P
    USN-791-1 -- moodle vulnerabilities
    2014-07-07
    oval:org.mitre.oval:def:13700
    P
    DSA-1761-1 moodle -- missing input sanitisation
    2014-06-23
    oval:org.mitre.oval:def:7916
    P
    DSA-1761 moodle -- missing input sanitisation
    2014-06-23
    oval:org.debian:def:1761
    V
    missing input sanitization
    2009-04-03
    BACK
    moodle moodle 1.6.4
    moodle moodle 1.6.1
    moodle moodle 1.7.1
    moodle moodle 1.8.5
    moodle moodle 1.8.4
    moodle moodle 1.9.3
    moodle moodle 1.6.7
    moodle moodle 1.6.8
    moodle moodle 1.7.6
    moodle moodle 1.8.2
    moodle moodle 1.8.1
    moodle moodle 1.8.8
    moodle moodle 1.9.4
    moodle moodle 1.6.3
    moodle moodle 1.6.5
    moodle moodle 1.6.0
    moodle moodle 1.7.4
    moodle moodle 1.7.5
    moodle moodle 1.8.3
    moodle moodle 1.8.6
    moodle moodle 1.9.2
    moodle moodle 1.9.1
    moodle moodle 1.6.2
    moodle moodle 1.6.6
    moodle moodle 1.7.3
    moodle moodle 1.7.2
    moodle moodle 1.8.7
    moodle moodle 1.6.2
    moodle moodle 1.7.1
    moodle moodle 1.8.3
    moodle moodle 1.7.5
    moodle moodle 1.7.4
    moodle moodle 1.7.3
    moodle moodle 1.7.2
    moodle moodle 1.6.5
    moodle moodle 1.6.4
    moodle moodle 1.6.3
    moodle moodle 1.6.1
    moodle moodle 1.6
    moodle moodle 1.7
    moodle moodle 1.6.6
    moodle moodle 1.8.4
    moodle moodle 1.8.2
    moodle moodle 1.8.5
    moodle moodle 1.6.7
    moodle moodle 1.9.2
    moodle moodle 1.9.1
    moodle moodle 1.9
    moodle moodle 1.8.1
    moodle moodle 1.8
    moodle moodle 1.8.6
    moodle moodle 1.9.3
    moodle moodle 1.8.7
    moodle moodle 1.7.6
    moodle moodle 1.6.8
    moodle moodle 1.9.4
    moodle moodle 1.8.8
    debian debian linux 4.0
    canonical ubuntu 8.04
    debian debian linux 5.0