CVE-2024-43426

A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

05 Aug 2025, 18:33

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2304254 - () https://bugzilla.redhat.com/show_bug.cgi?id=2304254 - Permissions Required
References () https://moodle.org/mod/forum/discuss.php?d=461194 - () https://moodle.org/mod/forum/discuss.php?d=461194 - Vendor Advisory
First Time Moodle
Moodle moodle
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

10 Feb 2025, 23:15

Type Values Removed Values Added
CWE CWE-1287

08 Nov 2024, 19:01

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en pdfTeX. Una desinfección insuficiente en el filtro de notación TeX resultó en un riesgo de lectura arbitraria de archivos en sitios donde pdfTeX está disponible, como aquellos con TeX Live instalado.

07 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-07 14:15

Updated : 2025-08-05 18:33


NVD link : CVE-2024-43426

Mitre link : CVE-2024-43426

CVE.ORG link : CVE-2024-43426


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-1287

Improper Validation of Specified Type of Input