
This repository serves as the public reference for CVE-2024-40445 and CVE-2024-40446. Both vulnerabilities impact MimeTeX, an open-source software package for rendering LaTeX expressions, which appears to be no longer maintained.
This repository serves as the public reference for the security issues CVE-2024-40445 and CVE-2024-40446 affecting MimeTeX, a lightweight open-source LaTeX renderer written in C.
⚠️ MimeTeX appears to be no longer actively maintained. Users and developers are strongly encouraged to assess the risks before using it in production environments.
A directory traversal vulnerability exists in MimeTeX prior to version 1.77. When operating in command-line or CGI mode, crafted user input can be used to perform unauthorized file access operations on Windows System.
MimeTeX versions from 1.76 up to 1.77 contain a code injection vulnerability. A malicious input string, when parsed by the engine, can trigger unintended command execution.
If you are a user of Moodle, which appears to be one of the main platforms still using MimeTeX, please refer to their advisory for mitigation guidance.
If you are using MimeTeX:
This repository is for informational purposes only. Technical details have been redacted to minimize potential risks to users and systems still using affected versions.
CVE IDs: CVE-2024-40445, CVE-2024-40446
Vendor: forkosh
Status: Affected versions are no longer actively maintained.