Vulnerability Description
Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated users to execute arbitrary code via ` (backtick) characters in a filename.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sharelatex | Sharelatex | <= 0.1.2 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/302668Third Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/302668Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-0934?
CVE-2015-0934 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated users to execute arbitrary code via ` (backtick) characters in a filename.
How severe is CVE-2015-0934?
CVE-2015-0934 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0934?
Check the references section above for vendor advisories and patch information. Affected products include: Sharelatex Sharelatex.