Lucene search

K
ubuntuUbuntuUSN-844-1
HistoryOct 08, 2009 - 12:00 a.m.

mimeTeX vulnerabilities

2009-10-0800:00:00
ubuntu.com
46

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.278

Percentile

96.8%

Releases

  • Ubuntu 9.04
  • Ubuntu 8.10
  • Ubuntu 8.04

Packages

  • mimetex -

Details

Chris Evans discovered that mimeTeX incorrectly handled certain long tags.
An attacker could exploit this with a crafted mimeTeX expression and cause
a denial of service or possibly execute arbitrary code. (CVE-2009-1382)

Chris Evans discovered that mimeTeX contained certain directives that may
be unsuitable for handling untrusted user input. This update fixed the
issue by disabling the \input and \counter tags. (CVE-2009-2459)

OSVersionArchitecturePackageVersionFilename
Ubuntu9.04noarchmimetex< 1.50-1ubuntu0.9.04.1UNKNOWN
Ubuntu8.10noarchmimetex< 1.50-1ubuntu0.8.10.1UNKNOWN
Ubuntu8.04noarchmimetex< 1.50-1ubuntu0.8.04.1UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.278

Percentile

96.8%