CVE-2024-40445

NameCVE-2024-40445
DescriptionA directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mimetex (PTS)bookworm, bullseye1.76-2fixed
sid, trixie1.76-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mimetexsource(unstable)(not affected)

Notes

- mimetex <not-affected> (Only affects MimeTeX on Windows, cf bug #1105117)
https://github.com/TaiYou-TW/CVE-2024-40445_CVE-2024-40446

Search for package or bug name: Reporting problems