CVE-2011-1400

medium
Published 2011-03-25 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
6.8

Description

The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

ubuntu Ubuntu Affected 2 releases
VersionStatusFixed in
10.10 Affected โ€”
10.04 Affected โ€”
debian Debian Mixed 6 releases
VersionStatusFixed in
trixie Fixed 2.09
sid Fixed 2.09
forky Fixed 2.09
bullseye Fixed 2.09
bookworm Fixed 2.09
โ€” Affected โ€”

Application impact

VendorProductVersionsFixed
debian debiantex-common0.1
debian debiantex-common0.2
debian debiantex-common0.3
debian debiantex-common0.4
debian debiantex-common0.5
debian debiantex-common0.6
debian debiantex-common0.7
debian debiantex-common0.8
debian debiantex-common0.9
debian debiantex-common0.10
debian debiantex-common0.11
debian debiantex-common0.12
debian debiantex-common0.13
debian debiantex-common0.14
debian debiantex-common0.15
debian debiantex-common0.16
debian debiantex-common0.17
debian debiantex-common0.18
debian debiantex-common0.19
debian debiantex-common0.20
debian debiantex-common0.21
debian debiantex-common0.22
debian debiantex-common0.23
debian debiantex-common0.24
debian debiantex-common0.25
debian debiantex-common0.26
debian debiantex-common0.27
debian debiantex-common0.28
debian debiantex-common0.29
debian debiantex-common0.30
debian debiantex-common0.31
debian debiantex-common0.32
debian debiantex-common0.33
debian debiantex-common0.34
debian debiantex-common0.35
debian debiantex-common0.36
debian debiantex-common0.37
debian debiantex-common0.38
debian debiantex-common0.39
debian debiantex-common0.40
debian debiantex-common0.41
debian debiantex-common0.42
debian debiantex-common0.43
debian debiantex-common0.44
debian debiantex-common1.0
debian debiantex-common1.1
debian debiantex-common1.2
debian debiantex-common1.3
debian debiantex-common1.4
debian debiantex-common1.5
debian debiantex-common1.6
debian debiantex-common1.7
debian debiantex-common1.8
debian debiantex-common1.9
debian debiantex-common1.10
debian debiantex-common1.11
debian debiantex-common1.11.1
debian debiantex-common1.11.2
debian debiantex-common1.11.3
debian debiantex-common1.12
debian debiantex-common1.13
debian debiantex-common1.14
debian debiantex-common1.15
debian debiantex-common1.16
debian debiantex-common1.17
debian debiantex-common1.18
debian debiantex-common1.19
debian debiantex-common1.20
debian debiantex-common2.00
debian debiantex-common2.01
debian debiantex-common2.02
debian debiantex-common2.03
debian debiantex-common2.04
debian debiantex-common2.05
debian debiantex-common2.06
debian debiantex-common2.07
debian debiantex-common2.08

References

CWEs

CWE-16

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.