Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10243

Опубликовано: 28 нояб. 2016
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6texliveNot affected
Red Hat Enterprise Linux 7texliveWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1429452texlive: mpost allows to run non-whitelisted external programs

EPSS

Процентиль: 94%
0.07146
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

CVSS3: 9.8
nvd
больше 9 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

CVSS3: 9.8
debian
больше 9 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leve ...

suse-cvrf
больше 2 лет назад

Security update for texlive-specs-k

CVSS3: 9.8
github
больше 4 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

EPSS

Процентиль: 94%
0.07146
Низкий

7 High

CVSS3