USN-791-2: Moodle vulnerability


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) USN-791-2: Moodle vulnerability
# 1  
Old 06-24-2009
USN-791-2: Moodle vulnerability

Referenced CVEs:
CVE-2009-1171


Description:
=========================================================== Ubuntu Security Notice USN-791-2 June 24, 2009 moodle vulnerability CVE-2009-1171 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 9.04: moodle 1.9.4.dfsg-0ubuntu1.1 After a standard system upgrade you need to access the Moodle instance and accept the database update to clear any invalid cached data. Details follow: Christian Eibl discovered that the TeX filter in Moodle allowed any function to be used. An authenticated remote attacker could post a specially crafted TeX formula to execute arbitrary TeX functions, potentially reading any file accessible to the web server user, leading to a loss of privacy. (CVE-2009-1171, MSA-09-0009)





More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
LIBMTP_devicestorage_struct(3)					      libmtp					    LIBMTP_devicestorage_struct(3)

NAME
libmtp - LIBMTP_devicestorage_struct SYNOPSIS
#include <libmtp.h> Data Fields uint32_t id uint16_t StorageType uint16_t FilesystemType uint16_t AccessCapability uint64_t MaxCapacity uint64_t FreeSpaceInBytes uint64_t FreeSpaceInObjects char * StorageDescription char * VolumeIdentifier LIBMTP_devicestorage_t * next LIBMTP_devicestorage_t * prev Detailed Description LIBMTP Device Storage structure Examples: folders.c, and sendtr.c. Field Documentation uint16_t LIBMTP_devicestorage_struct::AccessCapability Access capability Referenced by LIBMTP_Dump_Device_Info(), and LIBMTP_Get_Storage(). uint16_t LIBMTP_devicestorage_struct::FilesystemType Filesystem type Referenced by LIBMTP_Dump_Device_Info(), and LIBMTP_Get_Storage(). uint64_t LIBMTP_devicestorage_struct::FreeSpaceInBytes Free space in bytes Referenced by LIBMTP_Dump_Device_Info(), and LIBMTP_Get_Storage(). uint64_t LIBMTP_devicestorage_struct::FreeSpaceInObjects Free space in objects Referenced by LIBMTP_Dump_Device_Info(), and LIBMTP_Get_Storage(). uint32_t LIBMTP_devicestorage_struct::id Unique ID for this storage Examples: folders.c, and sendtr.c. Referenced by LIBMTP_Dump_Device_Info(), LIBMTP_Format_Storage(), and LIBMTP_Get_Storage(). uint64_t LIBMTP_devicestorage_struct::MaxCapacity Maximum capability Referenced by LIBMTP_Dump_Device_Info(), and LIBMTP_Get_Storage(). LIBMTP_devicestorage_t* LIBMTP_devicestorage_struct::next Next storage, follow this link until NULL Examples: folders.c, and sendtr.c. Referenced by LIBMTP_Dump_Device_Info(), and LIBMTP_Get_Storage(). LIBMTP_devicestorage_t* LIBMTP_devicestorage_struct::prev Previous storage Referenced by LIBMTP_Get_Storage(). char* LIBMTP_devicestorage_struct::StorageDescription A brief description of this storage Examples: folders.c, and sendtr.c. Referenced by LIBMTP_Dump_Device_Info(), and LIBMTP_Get_Storage(). uint16_t LIBMTP_devicestorage_struct::StorageType Storage type Referenced by LIBMTP_Dump_Device_Info(), and LIBMTP_Get_Storage(). char* LIBMTP_devicestorage_struct::VolumeIdentifier A volume identifier Referenced by LIBMTP_Dump_Device_Info(), and LIBMTP_Get_Storage(). Author Generated automatically by Doxygen for libmtp from the source code. Version 1.1.3 Sun Feb 17 2013 LIBMTP_devicestorage_struct(3)