CVE-2015-0296: Tug Texlive

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allows local users to delete arbitrary files via a crafted file in the user's home directory.

Affected products

  • Tug Texlive: version 6.20131226_r32488.fc20 only; version 3.1.20140525_r34255.fc21 only

Published 2017-10-06. Last modified 2026-06-17.