CVE-2015-0296

NONE EPSS 31.7%
Published Oct 6, 20178y ago · Modified Jun 17, 20262w ago
Find Similar
Published Oct 6, 2017 8y ago
Last Modified Jun 17, 2026 2w ago

Description

The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allows local users to delete arbitrary files via a crafted file in the user's home directory.

Threat Intelligence

EPSS Exploit Probability
31.7% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-264

Affected Products 4

VendorProductVersionRange
tugtexlive6.20131226_r32488.fc20any
fedoraprojectfedora20any
tugtexlive3.1.20140525_r34255.fc21any
fedoraprojectfedora21any

References 5

  • lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154198.html
    Third Party Advisory
  • lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154424.html
    Third Party Advisory
  • openwall.com http://www.openwall.com/lists/oss-security/2015/02/27/6
    Mailing ListThird Party Advisory
  • securityfocus.com http://www.securityfocus.com/bid/72826
    Third Party AdvisoryVDB Entry
  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=1197082
    Issue TrackingThird Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.