CVE-2011-1400
Severity CVSS v4.0:
Pending analysis
Type:
CWE-16
Configuration Errors
Publication date:
25/03/2011
Last modified:
11/04/2025
Description
The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:debian:tex-common:0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.13:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.14:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:tex-common:0.15:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/43816
- http://secunia.com/advisories/43973
- http://svn.debian.org/wsvn/debian-tex/?op=comp&compare%5B0%5D=/tex-common/trunk%404781&compare%5B1%5D=/tex-common/trunk%404812
- http://svn.debian.org/wsvn/debian-tex/tex-common/trunk/?op=log
- http://www.debian.org/security/2011/dsa-2198
- http://www.securityfocus.com/bid/46986
- http://www.ubuntu.com/usn/USN-1103-1
- http://www.vupen.com/english/advisories/2011/0731
- http://www.vupen.com/english/advisories/2011/0861
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66249
- http://secunia.com/advisories/43816
- http://secunia.com/advisories/43973
- http://svn.debian.org/wsvn/debian-tex/?op=comp&compare%5B0%5D=/tex-common/trunk%404781&compare%5B1%5D=/tex-common/trunk%404812
- http://svn.debian.org/wsvn/debian-tex/tex-common/trunk/?op=log
- http://www.debian.org/security/2011/dsa-2198
- http://www.securityfocus.com/bid/46986
- http://www.ubuntu.com/usn/USN-1103-1
- http://www.vupen.com/english/advisories/2011/0731
- http://www.vupen.com/english/advisories/2011/0861
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66249



