Ubuntu 8.04 LTS / 8.10 / 9.04 : mimetex vulnerabilities (USN-844-1)

Ubuntu Security Notice (C) 2009-2013 Canonical, Inc. / NASL script (C) 2009-2013 Tenable Network Security, Inc.

Synopsis :

The remote Ubuntu host is missing a security-related patch.

Description :

Chris Evans discovered that mimeTeX incorrectly handled certain long
tags. An attacker could exploit this with a crafted mimeTeX expression
and cause a denial of service or possibly execute arbitrary code.

Chris Evans discovered that mimeTeX contained certain directives that
may be unsuitable for handling untrusted user input. This update fixed
the issue by disabling the \input and \counter tags. (CVE-2009-2459).

Solution :

Update the affected mimetex package.

Risk factor :

Critical / CVSS Base Score : 10.0

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 42079 ()

Bugtraq ID:

CVE ID: CVE-2009-1382