{"id":"CVE-2015-5700","details":"mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.","modified":"2026-04-10T03:46:24.995965Z","published":"2017-08-25T18:29:00Z","references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2015/07/30/6"},{"type":"ADVISORY","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775139"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1181167"},{"type":"ADVISORY","url":"https://www.tug.org/svn/texlive/trunk/Build/source/texk/kpathsea/mktexlsr?r1=19613&r2=22885"},{"type":"ADVISORY","url":"https://www.tug.org/svn/texlive/trunk/Build/source/texk/kpathsea/mktexlsr?view=log"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2015/07/30/6"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1181167"},{"type":"FIX","url":"https://www.tug.org/svn/texlive/trunk/Build/source/texk/kpathsea/mktexlsr?r1=19613&r2=22885"},{"type":"REPORT","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775139"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1181167"},{"type":"WEB","url":"https://usn.ubuntu.com/3788-1/"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"}]}