Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 21: FEDORA-2015-4872 moderate: texlive file deletion

fedora
Calendar Grey April 8, 2015
Dist Fedora Esm H88
Resolving a vulnerability in the texlive scriptlet that facilitated unauthorized file deletions by non-privileged users in Fedora 21.
CVE-2015-0296 texlive rpm scriptlet allows unprivileged user to delete arbitrary files

Summary

The TeX Live software distribution offers a complete TeX system for a

variety of Unix, Macintosh, Windows and other platforms. It

encompasses programs for editing, typesetting, previewing and printing

of TeX documents in many different languages, and a large collection

of TeX macros and font libraries.

The distribution includes extensive general documentation about TeX,

as well as the documentation for the included software packages.

Update Information:

CVE-2015-0296 texlive rpm scriptlet allows unprivileged user to delete arbitrary files. This update fixes this issue

Change Log

* Thu Mar 26 2015 Than Ngo - 4:2014-3.1.20140525_r34255 - bump release and rebuild * Fri Mar 20 2015 Than Ngo - 4:2014-3.20140525_r34255 - bump release and rebuild * Fri Feb 27 2015 Than Ngo - 4:2014-2.20140525_r34255 - bz#1197084, Security fix for CVE-2015-0296 * Mon Aug 18 2014 Fedora Release Engineering - 4:2014-1.1.20140525_r34255.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild

References


[ 1 ] Bug #1197082 - CVE-2015-0296 texlive rpm scriptlet allows unprivileged user to delete arbitrary files https://bugzilla.redhat.com/show_bug.cgi?id=1197082

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update texlive' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: texlive
Product: Fedora 21
Version: 2014
Release: 3.1.20140525_r34255.fc21
Summary: TeX formatting system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here