Collected research
Are Text-Only Data Formats Safe? Or, Use This LaTeX Class File to Pwn Your Computer
Are Text-Only Data Formats Safe? Or, Use This LaTeX Class File to Pwn Your Computer (Paper)
Studies malicious TeX in online document and equation previewers. File I/O, command construction, character-category changes and aliases evade simple text filters even when shell execution is disabled. The paper compares vulnerable and isolated services, distinguishing demonstrated file disclosure from hypothetical file-write execution paths.
Record
- Document
- Are Text-Only Data Formats Safe? Or, Use This LaTeX Class File to Pwn Your Computer (Paper)
- Researcher
- Stephen Checkoway, Hovav Shacham and Eric Rescorla
- Published by
- USENIX
- Date
- Format
- Whitepaper
- Topic
- Other
In the archive
Related sources
- Are Text-Only Data Formats Safe? (Slides) Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Stephen Checkoway, Hovav Shacham and Eric Rescorla, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .