Back to Database
Status published
Medium
CVE-2007-5940
feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows...
Vulnerability Description
feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the feynmf$$.pl temporary file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-5940
Credits & Attribution
No credits recorded in the NVD database.
References
More from tug
View All →CVE-2018-17407
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files...
High
7.8
CVE-2017-17513
TeX Live through 20170524 does not validate strings before launching...
High
8.8
CVE-2015-5701
mktexlsr revision 36855, and before revision 36626 as packaged in...
Medium
6.1
CVE-2015-5700
mktexlsr revision 22855 through revision 36625 as packaged in texlive...
Medium
6.1
CVE-2015-0296
The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora...
Medium
4.7
Affected Vendor
Affected Software
texlive 2007
Vulnerable Versions:
Unknown
Timeline
Official Publish:
November 13th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.