An vulnerability in the handling of Latex exists in Ankitects...
Vulnerability Description
An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. An attacker can share a flashcard to trigger this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-29073
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Discovered by Autumn Bee Skerritt of Cisco Duo Security and Jacob B.
More from Ankitects
View All →Affected Vendor
Ankitects
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.