CVE-2009-1383
The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute arbitrary commands via shell metacharacters in the dpi tag.
Date published : 2009-07-14
http://www.securityfocus.com/archive/1/504919/100/0/threaded
http://groups.google.com/group/comp.text.tex/browse_thread/thread/5d56d3d744351578