Bug 692074 (CVE-2011-1400)

Summary: CVE-2011-1400 tetex, texlive: shell_escape_commands insufficient input sanitization (ACE)
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jnovy, pertusus
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-04-06 07:36:31 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jan Lieskovsky 2011-03-30 11:19:32 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1400 to
the following vulnerability:

The default configuration of the shell_escape_commands directive in
conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in
Debian GNU/Linux squeeze lists certain programs, which might allow
remote attackers to execute arbitrary code via a crafted TeX document.

References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1400
[2] http://svn.debian.org/wsvn/debian-tex/?op=comp&compare[]=%2Ftex-common%2Ftrunk@4781&compare[]=%2Ftex-common%2Ftrunk@4812
[3] http://svn.debian.org/wsvn/debian-tex/tex-common/trunk/?op=log
[4] http://www.debian.org/security/2011/dsa-2198
[5] http://www.securityfocus.com/bid/46986
[6] http://secunia.com/advisories/43816
[7] http://www.vupen.com/english/advisories/2011/0731
[8] http://xforce.iss.net/xforce/xfdb/66249

Comment 6 Huzaifa S. Sidhpurwala 2011-04-06 07:35:30 UTC
Statement:

Not vulnerable. This issue did not affect the versions of tetex as shipped with Red Hat Enterprise Linux 4 or 5, and the versions of texlive as shipped with Red Hat Enterprise Linux 6.

Comment 7 Huzaifa S. Sidhpurwala 2011-04-06 07:36:31 UTC
This issue does NOT affect the versions of texlive shipped with Fedora 13 or Fedora 14.