Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69334
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2198-1)
Summary:The remote host is missing an update for the Debian 'tex-common' package(s) announced via the DSA-2198-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'tex-common' package(s) announced via the DSA-2198-1 advisory.

Vulnerability Insight:
Mathias Svensson discovered that tex-common, a package shipping a number of scripts and configuration files necessary for TeX, contains insecure settings for the shell_escape_commands directive. Depending on the scenario, this may result in arbitrary code execution when a victim is tricked into processing a malicious tex-file or this is done in an automated fashion.

The oldstable distribution (lenny) is not affected by this problem due to shell_escape being disabled.

For the stable distribution (squeeze), this problem has been fixed in version 2.08.1.

For the testing (wheezy) and unstable (sid) distributions, this problem will be fixed soon.

We recommend that you upgrade your tex-common packages.

Affected Software/OS:
'tex-common' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1400
BugTraq ID: 46986
http://www.securityfocus.com/bid/46986
Debian Security Information: DSA-2198 (Google Search)
http://www.debian.org/security/2011/dsa-2198
http://secunia.com/advisories/43816
http://secunia.com/advisories/43973
http://www.ubuntu.com/usn/USN-1103-1
http://www.vupen.com/english/advisories/2011/0731
http://www.vupen.com/english/advisories/2011/0861
XForce ISS Database: texcommon-shellescapecommands-ce(66249)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66249
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.