CVE Vulnerabilities

CVE-2024-32152

Published: Jul 22, 2024 | Modified: Sep 06, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trigger this vulnerability.

Affected Software

Name Vendor Start Version End Version
Anki Ankitects 24.04 (including) 24.04 (including)

References