Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10243

Опубликовано: 02 мая 2017
Источник: debian

Описание

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
texlive-binfixed2019.20190605.51237-2package
texlive-basefixed2016.20161130-1package

Примечания

  • https://scumjr.github.io/2016/11/28/pwning-coworkers-thanks-to-latex/

  • http://www.tug.org/svn/texlive?view=revision&revision=42605

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

CVSS3: 7
redhat
больше 9 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

CVSS3: 9.8
nvd
больше 9 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

suse-cvrf
больше 2 лет назад

Security update for texlive-specs-k

CVSS3: 9.8
github
больше 4 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.