Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10243

Опубликовано: 28 нояб. 2016
Источник: redhat
CVSS3: 7

Описание

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6texliveNot affected
Red Hat Enterprise Linux 7texliveWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1429452texlive: mpost allows to run non-whitelisted external programs

7 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

CVSS3: 9.8
nvd
почти 9 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

CVSS3: 9.8
debian
почти 9 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leve ...

suse-cvrf
почти 2 года назад

Security update for texlive-specs-k

CVSS3: 9.8
github
больше 3 лет назад

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

7 High

CVSS3