A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
History

Mon, 10 Feb 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Weaknesses CWE-1287
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Vendors & Products Moodle
Moodle moodle
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 07 Nov 2024 13:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
Title Moodle: arbitrary file read risk through pdftex
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2025-02-10T22:27:06.037Z

Reserved: 2024-08-13T07:15:00.597Z

Link: CVE-2024-43426

cve-icon Vulnrichment

Updated: 2024-11-07T14:43:03.062Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-07T14:15:15.510

Modified: 2025-02-10T23:15:14.460

Link: CVE-2024-43426

cve-icon Redhat

No data.