CVE-2015-0296
NONE EPSS 31.7%
Published Oct 6, 20178y ago · Modified Jun 17, 20262w ago
Published Oct 6, 2017 8y ago
Last Modified Jun 17, 2026 2w ago
Description
The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allows local users to delete arbitrary files via a crafted file in the user's home directory.
Threat Intelligence
EPSS Exploit Probability
31.7% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-264
Affected Products 4
| Vendor | Product | Version | Range |
|---|---|---|---|
| tug | texlive | 6.20131226_r32488.fc20 | any |
| fedoraproject | fedora | 20 | any |
| tug | texlive | 3.1.20140525_r34255.fc21 | any |
| fedoraproject | fedora | 21 | any |
References 5
- lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154198.html
- lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154424.html
- openwall.com http://www.openwall.com/lists/oss-security/2015/02/27/6
- securityfocus.com http://www.securityfocus.com/bid/72826
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=1197082
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.