CVE-2015-5701 - Overview, Insights & Trends

CVE-2015-5701

Published Aug 25, 2017

Last updated 21 days ago

Overview

Description
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due to the reversion of a fix of CVE-2015-5700.
Source
cve@mitre.org
NVD status
Deferred

Risk scores

CVSS 3.0

Type
Primary
Base score
6.1
Impact score
4.2
Exploitability score
1.8
Vector string
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
5.6
Impact score
7.8
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:P/I:C/A:N

Weaknesses

nvd@nist.gov
CWE-59

Social media

Hype score
Not currently trending

Configurations