Reply to post: Re: Clay Tablets

Zero-day vuln in Microsoft Office: 'Follina' will work even when macros are disabled

Michael Wojcik Silver badge

Re: Clay Tablets

vi: modeline vulnerabilities. See for example this summary of modeline vulnerabilities in vim. I recall discussions of modeline vulnerabilities in classic vi from comp.unix.security circa 1990.

LaTeX: I don't offhand recall any published vulnerabilites for LaTeX2e itself, but TeX has always been vulnerable to various filesystem-access attacks, and assorted TeX implementations and backends such as MikTeX and pdfTeX have had them. Web-based LaTeX processors have had scads. (And, of course, if you're targeting PDF for output ... well, PDF, y'know? There are probably vulnerabilities in dvi implementations too.)

Mind you, I'd much rather use vim and LaTeX, or LyX, to write documents than Word, which is horrible. But the LaTeX toolchains are very complicated and expecting them to be free of vulnerabilities is naive. Better than MS Office, sure, but nothing's perfect.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon