The (1) texmacs and (2) tmmupadhelp scripts in TeXmacs 1.0.7.4 place a zero-length directory name in the LDLIBRARYPATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1:1.0.7.18-1", "binary_name": "texmacs" }, { "binary_version": "1:1.0.7.18-1", "binary_name": "texmacs-common" } ] }