PT-2024-22699 · Ankitects+1 · Anki+1
Autumn Bee
+2
·
Published
2024-07-22
·
Updated
2024-10-07
·
CVE-2024-29073
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ankitects Anki version 24.04
Description
A vulnerability exists in the handling of Latex, where the verbatim package has been overlooked during sanitization to prevent unsafe commands. This can lead to an arbitrary file read when a specially crafted flashcard is shared by an attacker.
Recommendations
For Ankitects Anki version 24.04, consider disabling the use of Latex or restricting the sharing of flashcards until a patch is available. As a temporary workaround, avoid using the verbatim package in Latex distributions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anki
Debian