CVE-2015-5701: Medium severity tex live vulnerability
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due to the reversion of a fix of CVE-2015-5700.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5701?
CVE-2015-5701 is considered a medium severity vulnerability due to its ability to allow local users to write to arbitrary files through a symlink attack.
How do I fix CVE-2015-5701?
To fix CVE-2015-5701, users should update their TeX Live installation to a version after revision 36855 that addresses this symlink vulnerability.
Who is affected by CVE-2015-5701?
CVE-2015-5701 affects users of TeX Live versions 20100722, 20110705, 20120701, 20130530, and 20140525.
What causes CVE-2015-5701?
CVE-2015-5701 is caused by the reversion of a fix for a previous vulnerability, CVE-2015-5700.
Can CVE-2015-5701 be exploited remotely?
CVE-2015-5701 cannot be exploited remotely as it requires local user access to execute the symlink attack.