CVE-2011-1400

tex-common < 2.08.1 - Remote Code Execution via TeX Document

Title source: llm
STIX 2.1

Description

The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/66249
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43973
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46986
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0731
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1103-1
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2198
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0861
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43816

Scores

EPSS 0.0406
EPSS Percentile 89.6%

Details

CWE
CWE-16
Status published
Products (50)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 10.10
debian/debian_linux
debian/tex-common 0.1
debian/tex-common 0.2
debian/tex-common 0.3
debian/tex-common 0.4
debian/tex-common 0.5
debian/tex-common 0.6
debian/tex-common 0.7
... and 40 more
Published Mar 25, 2011
Tracked Since Feb 18, 2026