PT-2022-11303 · Latex+1 · Latex+1

Dhananjay Arunesh

·

Published

2021-09-13

·

Updated

2024-03-06

·

CVE-2021-40694

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue is related to insufficient escaping of the LaTeX preamble, which allows site administrators to read files available to the HTTP server system account. This could potentially lead to unauthorized access to sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2787
ALT-PU-2021-3335
ALT-PU-2022-1641
BIT-MOODLE-2021-40694
CVE-2021-40694
GHSA-M37G-MWCG-7J7V

Affected Products

Alt Linux
Latex