Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8106

Опубликовано: 18 апр. 2016
Источник: debian
EPSS Низкий

Описание

Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
latex2rtffixed2.3.10-1package
latex2rtfnot-affectedwheezypackage
latex2rtfnot-affectedsqueezepackage

Примечания

  • keywords command support introduced in http://sourceforge.net/p/latex2rtf/code/1152

  • http://sourceforge.net/p/latex2rtf/code/1152/tree//trunk/funct1.c?diff=50900fed34309d3c639c868f:1151

  • latex2rtf compiled with -D_FORTIFY_SOURCE=2

  • Rendered non-exploitable by toolchain hardening

EPSS

Процентиль: 75%
0.00877
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 10 лет назад

Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.

CVSS3: 7.8
nvd
почти 10 лет назад

Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.

CVSS3: 7.8
github
больше 3 лет назад

Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.

EPSS

Процентиль: 75%
0.00877
Низкий