Executive Summary

Informations
Name CVE-2009-2459 First vendor Publication 2009-07-14
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2459

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:13175
 
Oval ID: oval:org.mitre.oval:def:13175
Title: USN-844-1 -- mimetex vulnerabilities
Description: Chris Evans discovered that mimeTeX incorrectly handled certain long tags. An attacker could exploit this with a crafted mimeTeX expression and cause a denial of service or possibly execute arbitrary code. Chris Evans discovered that mimeTeX contained certain directives that may be unsuitable for handling untrusted user input. This update fixed the issue by disabling the \input and \counter tags
Family: unix Class: patch
Reference(s): USN-844-1
CVE-2009-1382
CVE-2009-2459
Version: 5
Platform(s): Ubuntu 8.10
Ubuntu 8.04
Ubuntu 9.04
Product(s): mimetex
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:13271
 
Oval ID: oval:org.mitre.oval:def:13271
Title: DSA-1917-1 mimetex -- several vulnerabilities
Description: Several vulnerabilities have been discovered in mimetex, a lightweight alternative to MathML. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1382 Chris Evans and Damien Miller, discovered multiple stack-based buffer overflow. An attacker could execute arbitrary code via a TeX file with long picture, circle, input tags. CVE-2009-2459 Chris Evans discovered that mimeTeX contained certain directives that may be unsuitable for handling untrusted user input. A remote attacker can obtain sensitive information. For the oldstable distribution, these problems have been fixed in version 1.50-1+etch1. Due to a bug in the archive system, the fix for the stable distribution will be released as version 1.50-1+lenny1 once it is available. For the testing distribution, and the unstable distribution, these problems have been fixed in version 1.50-1.1. We recommend that you upgrade your mimetex packages.
Family: unix Class: patch
Reference(s): DSA-1917-1
CVE-2009-1382
CVE-2009-2459
Version: 5
Platform(s): Debian GNU/Linux 4.0
Product(s): mimetex
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:8178
 
Oval ID: oval:org.mitre.oval:def:8178
Title: DSA-1917 mimetex -- several vulnerabilities
Description: Several vulnerabilities have been discovered in mimetex, a lightweight alternative to MathML. The Common Vulnerabilities and Exposures project identifies the following problems: Chris Evans and Damien Miller, discovered multiple stack-based buffer overflow. An attacker could execute arbitrary code via a TeX file with long picture, circle, input tags. Chris Evans discovered that mimeTeX contained certain directives that may be unsuitable for handling untrusted user input. A remote attacker can obtain sensitive information.
Family: unix Class: patch
Reference(s): DSA-1917
CVE-2009-1382
CVE-2009-2459
Version: 3
Platform(s): Debian GNU/Linux 4.0
Product(s): mimetex
Definition Synopsis:

OpenVAS Exploits

Date Description
2010-04-16 Name : Fedora Update for mimetex FEDORA-2010-6546
File : nvt/gb_fedora_2010_6546_mimetex_fc12.nasl
2009-11-11 Name : Fedora Core 11 FEDORA-2009-10170 (mimetex)
File : nvt/fcore_2009_10170.nasl
2009-11-11 Name : Fedora Core 10 FEDORA-2009-10225 (mimetex)
File : nvt/fcore_2009_10225.nasl
2009-10-27 Name : Debian Security Advisory DSA 1917-1 (mimetex)
File : nvt/deb_1917_1.nasl
2009-10-13 Name : Ubuntu USN-844-1 (mimetex)
File : nvt/ubuntu_844_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
56099 mimeTeX Multiple TeX Directives Unspecified Issue

Nessus® Vulnerability Scanner

Date Description
2013-03-24 Name : The remote Fedora host is missing a security update.
File : fedora_2013-3902.nasl - Type : ACT_GATHER_INFO
2013-03-24 Name : The remote Fedora host is missing a security update.
File : fedora_2013-3910.nasl - Type : ACT_GATHER_INFO
2010-07-01 Name : The remote Fedora host is missing a security update.
File : fedora_2010-6546.nasl - Type : ACT_GATHER_INFO
2010-02-24 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1917.nasl - Type : ACT_GATHER_INFO
2009-11-05 Name : The remote Fedora host is missing a security update.
File : fedora_2009-10170.nasl - Type : ACT_GATHER_INFO
2009-11-05 Name : The remote Fedora host is missing a security update.
File : fedora_2009-10225.nasl - Type : ACT_GATHER_INFO
2009-10-09 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-844-1.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039314.html
http://scary.beasts.org/security/CESA-2009-009.html
http://secunia.com/advisories/35752
http://www.vupen.com/english/advisories/2009/1875
http://www.vupen.com/english/advisories/2010/0877
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
Date Informations
2024-11-28 23:10:52
  • Multiple Updates
2024-11-28 12:19:24
  • Multiple Updates
2021-04-22 01:10:09
  • Multiple Updates
2020-05-23 01:40:37
  • Multiple Updates
2020-05-23 00:24:02
  • Multiple Updates
2016-04-26 18:58:22
  • Multiple Updates
2014-02-17 10:50:45
  • Multiple Updates
2013-05-10 23:53:54
  • Multiple Updates