A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Sep 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows |
MITRE
Status: PUBLISHED
Assigner: talos
Published: 2024-07-22T14:20:26.096Z
Updated: 2024-08-02T02:06:44.097Z
Reserved: 2024-05-06T16:39:15.937Z
Link: CVE-2024-32152
Vulnrichment
Updated: 2024-07-22T14:53:11.223Z
NVD
Status : Modified
Published: 2024-07-22T15:15:03.197
Modified: 2024-11-21T09:14:33.683
Link: CVE-2024-32152
Redhat
No data.