[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4299-1 texlive-bin -- texlive-bin

ID: oval:org.secpod.oval:def:603524Date: (C)2018-10-01   (M)2023-12-20
Class: PATCHFamily: unix




Nick Roessler from the University of Pennsylvania has found a buffer overflow in texlive-bin, the executables for TexLive, the popular distribution of TeX document production system. This buffer overflow can be used for arbitrary code execution by crafting a special type1 font and provide it to users running pdftex, dvips or luatex in a way that the font is loaded.

Platform:
Debian 9.x
Product:
libptexenc-dev
libkpathsea-dev
texlive-binaries
libtexluajit2
libtexluajit-dev
libkpathsea6
libtexlua52
libsynctex-dev
libptexenc1
libsynctex1
Reference:
DSA-4299-1
CVE-2018-17407
CVE    1
CVE-2018-17407
CPE    4
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:9.x
cpe:/a:tug:texlive-binaries
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies