CVE-2015-0296Command Injection in Texlive

Severity
4.7MEDIUMNVD
EPSS
0.1%
top 75.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6
Latest updateMay 17

Description

The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allows local users to delete arbitrary files via a crafted file in the user's home directory.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages2 packages

NVDtug/texlive3.1.20140525_r34255.fc21, 6.20131226_r32488.fc20+1

🔴Vulnerability Details

1
GHSA
GHSA-8vr6-57gw-vwjf: The pre-install script in texlive 32022-05-17

📋Vendor Advisories

2
Debian
CVE-2015-0296: texlive-base - The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora...2015
Red Hat
texlive rpm scriptlet allows unprivileged user to delete arbitrary files2014-05-19

💬Community

3
Bugzilla
CVE-2015-0296 texlive: texlive rpm scriptlet allows unprivileged user to delete arbitrary files [fedora-all]2015-02-27
Bugzilla
CVE-2015-0296 texlive rpm scriptlet allows unprivileged user to delete arbitrary files2015-02-27
Bugzilla
CVE-2015-1200 pxz: race condition in setting permissions on output file2015-01-14