An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. An attacker can share a flashcard to trigger this vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Sep 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ankiweb
Ankiweb anki |
|
CPEs | cpe:2.3:a:ankiweb:anki:24.04:*:*:*:*:*:*:* | |
Vendors & Products |
Ankiweb
Ankiweb anki |

Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-02T01:03:51.703Z
Reserved: 2024-05-06T16:38:05.004Z
Link: CVE-2024-29073

Updated: 2024-07-22T16:41:59.136Z

Status : Modified
Published: 2024-07-22T15:15:02.943
Modified: 2024-11-21T09:07:30.007
Link: CVE-2024-29073

No data.