Back to Database
Status published
High
CVE-2009-2461
mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely...
Vulnerability Description
mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2461
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vupen.com/english/advisories/2009/1875
- http://www.securityfocus.com/archive/1/504919/100/0/threaded
- http://secunia.com/advisories/35816
- http://www.ocert.org/advisories/ocert-2009-010.html
- http://groups.google.com/group/comp.text.tex/browse_thread/thread/5d56d3d744351578
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51797
More from forkosh
View All →CVE-2009-2460
Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded...
Critical
10
CVE-2009-2459
Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have...
Critical
10
CVE-2009-1383
The getdirective function in mathtex.cgi in mathTeX, when downloaded before...
High
7.5
CVE-2009-1382
Multiple stack-based buffer overflows in mimetex.cgi in mimeTeX, when downloaded...
Critical
10
Affected Vendor
forkosh
View all reports →Affected Software
mathtex
Vulnerable Versions:
0, 1.00, 1.01
Timeline
Official Publish:
July 14th, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.