CVE-2024-29073

An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. An attacker can share a flashcard to trigger this vulnerability.
References
Link Resource
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1992 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ankiweb:anki:24.04:*:*:*:*:*:*:*

History

18 Sep 2024, 18:31

Type Values Removed Values Added
CWE CWE-829

11 Sep 2024, 14:53

Type Values Removed Values Added
CPE cpe:2.3:a:ankiweb:anki:24.04:*:*:*:*:*:*:*
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1992 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1992 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5
First Time Ankiweb
Ankiweb anki

22 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 15:15

Updated : 2024-09-18 18:31


NVD link : CVE-2024-29073

Mitre link : CVE-2024-29073


JSON object : View

Products Affected

ankiweb

  • anki
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere