PT-2007-2106 · Tetex · Makeindex

Mark Richters

·

Publicado

2007-02-01

·

Atualizado

2017-07-29

·

CVE-2007-0650

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions makeindex version 2.14 in teTeX
Description A buffer overflow issue exists in the open sty function in mkind.c, potentially allowing user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename. Other overflows, such as a heap-based overflow in the check idx function, might also exist but their exploitability is uncertain.
Recommendations For makeindex version 2.14 in teTeX, consider restricting the length of filenames to prevent potential buffer overflows until a patch is available. As a temporary workaround, avoid using long filenames with the open sty function to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0650

Produtos afetados

Makeindex