TeX Live CVE-2015-0296 Local Arbitrary File Deletion Vulnerability
BID:72826
CVE-2015-296 |Info
TeX Live CVE-2015-0296 Local Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 72826 |
| Class: | Design Error |
| CVE: |
CVE-2015-0296 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 02 2015 12:00AM |
| Updated: | Jul 15 2015 12:21AM |
| Credit: | Siddharth Sharma |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
TeX Live CVE-2015-0296 Local Arbitrary File Deletion Vulnerability
TeX Live is prone to a local arbitrary-file-deletion vulnerability.
Local attackers can exploit this issue to delete arbitrary files in the context of the affected system. This may lead to further attacks.
TeX Live is prone to a local arbitrary-file-deletion vulnerability.
Local attackers can exploit this issue to delete arbitrary files in the context of the affected system. This may lead to further attacks.
Exploit / POC
TeX Live CVE-2015-0296 Local Arbitrary File Deletion Vulnerability
Attackers require local interactive access to exploit this issue.
Attackers require local interactive access to exploit this issue.
Solution / Fix
TeX Live CVE-2015-0296 Local Arbitrary File Deletion Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
TeX Live CVE-2015-0296 Local Arbitrary File Deletion Vulnerability
References:
References:
- Tex Live Homepage (Tex Live)