CVE-2024-29073

An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. An attacker can share a flashcard to trigger this vulnerability.
References
Link Resource
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1992 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ankiweb:anki:24.04:*:*:*:*:*:*:*

History

11 Sep 2024, 14:53

Type Values Removed Values Added
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1992 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1992 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5
First Time Ankiweb anki
Ankiweb
CPE cpe:2.3:a:ankiweb:anki:24.04:*:*:*:*:*:*:*

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad en el manejo de Latex en Ankitects Anki 24.04. Cuando se desinfecta Latex para evitar comandos inseguros, se pasa por alto el paquete verbatim, que viene instalado de forma predeterminada en muchas distribuciones de Latex. Una tarjeta flash especialmente manipulada puede provocar la lectura de un archivo arbitrario. Un atacante puede compartir una tarjeta didáctica para desencadenar esta vulnerabilidad.

22 Jul 2024, 17:15

Type Values Removed Values Added
References
  • {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1992', 'source': 'talos-cna@cisco.com'}

22 Jul 2024, 16:15

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1992 -

22 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 15:15

Updated : 2024-09-18 18:31


NVD link : CVE-2024-29073

Mitre link : CVE-2024-29073

CVE.ORG link : CVE-2024-29073


JSON object : View

Products Affected

ankiweb

  • anki
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere