|
|
| |
|
| |
mimetex: multiple vulnerabilities
| Package(s): | mimetex |
CVE #(s): | CVE-2009-1382
CVE-2009-2459
|
| Created: | October 8, 2009 |
Updated: | March 25, 2013 |
| Description: |
From the Ubuntu alert:
Chris Evans discovered that mimeTeX incorrectly handled certain long tags.
An attacker could exploit this with a crafted mimeTeX expression and cause
a denial of service or possibly execute arbitrary code. (CVE-2009-1382)
Chris Evans discovered that mimeTeX contained certain directives that may
be unsuitable for handling untrusted user input. This update fixed the
issue by disabling the \input and \counter tags. (CVE-2009-2459) |
| Alerts: |
|
( Log in to post comments)
|
|
|