CVE-2011-1400
published 2011-03-25CVE-2011-1400: The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux…
PriorityP339medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.06%
89.6th percentile
The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | tex-common | < tex-common 2.09 (bookworm) | tex-common 2.09 (bookworm) |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
| debian | tex-common | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
tex-common vulnerability
vendor_ubuntu·2011-04-04
CVE-2011-1400 tex-common vulnerability
Title: tex-common vulnerability
Summary: tex-common could be made to run programs as your login if it opened a
specially crafted file.
Mathias Svensson discovered that the tex-common package contains an
insecure shell_escape_commands configuration item. If a user or automated
system were tricked into opening a specially crafted TeX file, a remote
attacker could execute arbitrary code with user privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
texlive: shell_escape_commands insufficient input sanitization (ACE)
vendor_redhat·2011-03-23·CVSS 6.8
CVE-2011-1400 [MEDIUM] texlive: shell_escape_commands insufficient input sanitization (ACE)
texlive: shell_escape_commands insufficient input sanitization (ACE)
The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
Statement: Not vulnerable. This issue did not affect the versions of tetex as shipped with Red Hat Enterprise Linux 4 or 5, and the versions of texlive as shipped with Red Hat Enterprise Linux 6.
Debian
CVE-2011-1400: tex-common - The default configuration of the shell_escape_commands directive in conf/texmf.d...
vendor_debian·2011·CVSS 6.8
CVE-2011-1400 [MEDIUM] CVE-2011-1400: tex-common - The default configuration of the shell_escape_commands directive in conf/texmf.d...
The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
Scope: local
bookworm: resolved (fixed in 2.09)
bullseye: resolved (fixed in 2.09)
forky: resolved (fixed in 2.09)
sid: resolved (fixed in 2.09)
trixie: resolved (fixed in 2.09)
GHSA
GHSA-3hcf-872f-8qrc: The default configuration of the shell_escape_commands directive in conf/texmf
ghsa_unreviewed·2022-05-14
CVE-2011-1400 [MEDIUM] GHSA-3hcf-872f-8qrc: The default configuration of the shell_escape_commands directive in conf/texmf
The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
OSV
CVE-2011-1400: The default configuration of the shell_escape_commands directive in conf/texmf
osv·2011-03-25·CVSS 6.8
CVE-2011-1400 [MEDIUM] CVE-2011-1400: The default configuration of the shell_escape_commands directive in conf/texmf
The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
Suricata
ET WEB_SERVER Apache APR apr_fnmatch Stack Overflow Denial of Service
suricata·2011-06-02
CVE-2011-0419 ET WEB_SERVER Apache APR apr_fnmatch Stack Overflow Denial of Service
ET WEB_SERVER Apache APR apr_fnmatch Stack Overflow Denial of Service
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SERVER Apache APR apr_fnmatch Stack Overflow Denial of Service"; flow:established,to_server; urilen:>1400; http.uri; content:"|2F 3F|P|3D 2A 3F 2A 3F 2A 3F 2A 3F 2A 3F|"; pcre:"/(?:\x2a\x3f){700}/"; reference:cve,2011-0419; reference:url,cxib.net/stuff/apr_fnmatch.txt; reference:url,bugzilla.redhat.com/show_bug.cgi?id=703390; classtype:attempted-dos; sid:2012926; rev:5; metadata:created_at 2011_06_02, cve CVE_2011_0419, confidence Medium, signature_severity Major, updated_at 2024_03_06;)
No public exploits indexed.
http://secunia.com/advisories/43816http://secunia.com/advisories/43973http://svn.debian.org/wsvn/debian-tex/?op=comp&compare%5B%5D=%2Ftex-common%2Ftrunk%404781&compare%5B%5D=%2Ftex-common%2Ftrunk%404812http://svn.debian.org/wsvn/debian-tex/tex-common/trunk/?op=loghttp://www.debian.org/security/2011/dsa-2198http://www.securityfocus.com/bid/46986http://www.ubuntu.com/usn/USN-1103-1http://www.vupen.com/english/advisories/2011/0731http://www.vupen.com/english/advisories/2011/0861https://exchange.xforce.ibmcloud.com/vulnerabilities/66249http://secunia.com/advisories/43816http://secunia.com/advisories/43973http://svn.debian.org/wsvn/debian-tex/?op=comp&compare%5B%5D=%2Ftex-common%2Ftrunk%404781&compare%5B%5D=%2Ftex-common%2Ftrunk%404812http://svn.debian.org/wsvn/debian-tex/tex-common/trunk/?op=loghttp://www.debian.org/security/2011/dsa-2198http://www.securityfocus.com/bid/46986http://www.ubuntu.com/usn/USN-1103-1http://www.vupen.com/english/advisories/2011/0731http://www.vupen.com/english/advisories/2011/0861https://exchange.xforce.ibmcloud.com/vulnerabilities/66249
2011-03-25
Published