PT-2024-24448 · Ankitects+1 · Anki+1

Autumn Bee

+2

·

Published

2024-07-22

·

Updated

2024-09-06

·

CVE-2024-32152

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ankitects Anki version 24.04
Description A blocklist bypass issue exists in the LaTeX functionality, allowing a specially crafted malicious flashcard to create an arbitrary file at a fixed path. An attacker can trigger this issue by sharing a malicious flashcard.
Recommendations For Ankitects Anki version 24.04, consider disabling the LaTeX functionality until a patch is available to prevent exploitation. Restrict access to the flashcard sharing feature to minimize the risk of arbitrary file creation.

Exploit

Fix

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2024-32152
GHSA-Q47P-V5RW-V574

Affected Products

Anki
Debian