Arbitrary File Read Vulnerability in pdfTeX by TeX Live Vendor
CVE-2024-43426

7.5HIGH

Key Information:

Vendor

Moodle

Status
Vendor
CVE Published:
7 November 2024

What is CVE-2024-43426?

A security flaw exists in pdfTeX due to insufficient sanitizing within the TeX notation filter, which may lead to unauthorized access of files on systems that have pdfTeX deployed, particularly those utilizing TeX Live. This vulnerability poses a significant risk, allowing attackers to read arbitrary files, potentially leading to data exposure.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.