A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2304254 | issue tracking |
https://moodle.org/mod/forum/discuss.php?d=461194 |