First published: Fri Aug 25 2017(Updated: )
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due to the reversion of a fix of CVE-2015-5700.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TUG TeX Live | =20100722 | |
TUG TeX Live | =20110705 | |
TUG TeX Live | =20120701 | |
TUG TeX Live | =20130530 | |
TUG TeX Live | =20140525 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5701 is considered a medium severity vulnerability due to its ability to allow local users to write to arbitrary files through a symlink attack.
To fix CVE-2015-5701, users should update their TeX Live installation to a version after revision 36855 that addresses this symlink vulnerability.
CVE-2015-5701 affects users of TeX Live versions 20100722, 20110705, 20120701, 20130530, and 20140525.
CVE-2015-5701 is caused by the reversion of a fix for a previous vulnerability, CVE-2015-5700.
CVE-2015-5701 cannot be exploited remotely as it requires local user access to execute the symlink attack.