CVE-2011-1400: Medium severity vim-common vulnerability
Published Mar 25, 2011
·Updated
The default configuration of the shellescapecommands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
Affected Software
80 affected components
Debian tex-common=0.1
Debian tex-common=0.2
Debian tex-common=0.3
Debian tex-common=0.4
Debian tex-common=0.5
Debian tex-common=0.6
Debian tex-common=0.7
Debian tex-common=0.8
Debian tex-common=0.9
Debian tex-common=0.10
Debian tex-common=0.11
Debian tex-common=0.12
Debian tex-common=0.13
Debian tex-common=0.14
Debian tex-common=0.15
Debian tex-common=0.16
Debian tex-common=0.17
Debian tex-common=0.18
Debian tex-common=0.19
Debian tex-common=0.20
Debian tex-common=0.21
Debian tex-common=0.22
Debian tex-common=0.23
Debian tex-common=0.24
Debian tex-common=0.25
Debian tex-common=0.26
Debian tex-common=0.27
Debian tex-common=0.28
Debian tex-common=0.29
Debian tex-common=0.30
Debian tex-common=0.31
Debian tex-common=0.32
Debian tex-common=0.33
Debian tex-common=0.34
Debian tex-common=0.35
Debian tex-common=0.36
Debian tex-common=0.37
Debian tex-common=0.38
Debian tex-common=0.39
Debian tex-common=0.40
Debian tex-common=0.41
Debian tex-common=0.42
Debian tex-common=0.43
Debian tex-common=0.44
Debian tex-common=1.0
Debian tex-common=1.1
Debian tex-common=1.2
Debian tex-common=1.3
Debian tex-common=1.4
Debian tex-common=1.5
Debian tex-common=1.6
Debian tex-common=1.7
Debian tex-common=1.8
Debian tex-common=1.9
Debian tex-common=1.10
Debian tex-common=1.11
Debian tex-common=1.11.1
Debian tex-common=1.11.2
Debian tex-common=1.11.3
Debian tex-common=1.12
Debian tex-common=1.13
Debian tex-common=1.14
Debian tex-common=1.15
Debian tex-common=1.16
Debian tex-common=1.17
Debian tex-common=1.18
Debian tex-common=1.19
Debian tex-common=1.20
Debian tex-common=2.00
Debian tex-common=2.01
Debian tex-common=2.02
Debian tex-common=2.03
Debian tex-common=2.04
Debian tex-common=2.05
Debian tex-common=2.06
Debian tex-common=2.07
Debian tex-common=2.08
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=10.10
Debian Debian Linux
Event History
Mar 25, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1400?
CVE-2011-1400 is classified as a medium severity vulnerability.
2
How do I fix CVE-2011-1400?
To fix CVE-2011-1400, update the tex-common package to version 2.08.1 or later.
3
What systems are affected by CVE-2011-1400?
CVE-2011-1400 affects Debian GNU/Linux squeeze and Ubuntu versions 10.10 and 10.04 LTS.
4
What does CVE-2011-1400 exploit?
CVE-2011-1400 exploits a misconfiguration in the shell_escape_commands directive.
5
Is CVE-2011-1400 related to remote code execution?
Yes, CVE-2011-1400 may allow remote attackers to execute arbitrary commands.