CVE-2011-1400

Severity CVSS v4.0:
Pending analysis
Type:
CWE-16 Configuration Errors
Publication date:
25/03/2011
Last modified:
11/04/2025

Description

The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:debian:tex-common:0.1:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.2:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.3:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.4:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.5:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.6:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.7:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.8:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.9:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.10:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.11:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.12:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.13:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.14:*:*:*:*:*:*:*
cpe:2.3:a:debian:tex-common:0.15:*:*:*:*:*:*:*