LWN.net Logo

mimetex: multiple vulnerabilities

Package(s):mimetex CVE #(s):CVE-2009-1382 CVE-2009-2459
Created:October 8, 2009 Updated:March 25, 2013
Description: From the Ubuntu alert:

Chris Evans discovered that mimeTeX incorrectly handled certain long tags. An attacker could exploit this with a crafted mimeTeX expression and cause a denial of service or possibly execute arbitrary code. (CVE-2009-1382)

Chris Evans discovered that mimeTeX contained certain directives that may be unsuitable for handling untrusted user input. This update fixed the issue by disabling the \input and \counter tags. (CVE-2009-2459)

Alerts:
Fedora FEDORA-2010-6546 2010-04-14
Fedora FEDORA-2009-10170 2009-10-03
Fedora FEDORA-2009-10225 2009-10-03
Debian DSA-1917-1 2009-10-24
Ubuntu USN-844-1 2009-10-08
Fedora FEDORA-2013-3910 2013-03-23
Fedora FEDORA-2013-3902 2013-03-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds