An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. An attacker can share a flashcard to trigger this vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Sep 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ankiweb
Ankiweb anki |
|
CPEs | cpe:2.3:a:ankiweb:anki:24.04:*:*:*:*:*:*:* | |
Vendors & Products |
Ankiweb
Ankiweb anki |
MITRE
Status: PUBLISHED
Assigner: talos
Published: 2024-07-22T14:20:27.250Z
Updated: 2024-08-02T01:03:51.703Z
Reserved: 2024-05-06T16:38:05.004Z
Link: CVE-2024-29073
Vulnrichment
Updated: 2024-07-22T16:41:59.136Z
NVD
Status : Modified
Published: 2024-07-22T15:15:02.943
Modified: 2024-11-21T09:07:30.007
Link: CVE-2024-29073
Redhat
No data.