Bug#1103801: CVE-2024-40446: code injection vulnerability

2025-05-09 Thread Hilmar Preuße
On 09.05.25 11:52, Shang-Hung, Wan wrote: Hello Shang-Hung, as you've noticed I've took my web page offline: running a web server carrying a vulnerable cgi script is probably not the best idea. ;-) There is a comment [1] that stated that he contacted the author John, and he said version 1.75

Bug#1103801: CVE-2024-40446: code injection vulnerability

2025-05-09 Thread Shang-Hung, Wan
Hello Hilmar, Yes, version 1.74 is not affected because I think the vulnerable feature was added in 1.76. (or 1.75, I can’t find the source code of 1.75 so I can’t make sure of it) There is a comment [1] that stated that he contacted the author John, and he said version 1.75 in the source code

Bug#1103801: CVE-2024-40446: code injection vulnerability

2025-05-08 Thread Hilmar Preuße
On 21.04.25 18:57, TaiYou wrote: Hello, A code injection vulnerability has been identified in MimeTeX, affecting version 1.76-1 and above. This issue has been assigned CVE-2024-40446. Are you sure that 1.76 and above is affected? I would rather think 1.76 and below is affected. Until now I