Tex Live · Texlive-Bin · CVE-2024-25262
Name of the Vulnerable Software and Affected Versions:
texlive-bin version c515e
Description:
The issue is related to a heap buffer overflow in the `ttfLoadHDMX:ttfdump` function of the texlive-bin component in TeX Live computer typesetting systems. This allows attackers to cause a Denial of Service (DoS) by supplying a crafted TTF file. The vulnerability can be exploited by a remote attacker to disrupt service.
Recommendations:
For texlive-bin version c515e, consider disabling the `ttfLoadHDMX:ttfdump` function as a temporary workaround until a patch is available to prevent potential Denial of Service attacks.