PT-2024-14316 · Mathtex+1 · Mathtex+1

Yulun Wu

·

Published

2024-01-24

·

Updated

2024-02-05

·

CVE-2023-51885

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mathtex versions 1.05 and earlier
Description The issue allows a remote attacker to execute arbitrary code via the length of the LaTeX string component. This can be exploited to gain unauthorized access and control over the system.
Recommendations For Mathtex versions 1.05 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-51885

Affected Products

Debian
Mathtex