PT-2007-2106 · Tetex · Makeindex

Mark Richters

·

Published

2007-02-01

·

Updated

2017-07-29

·

CVE-2007-0650

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions makeindex version 2.14 in teTeX
Description A buffer overflow issue exists in the open sty function in mkind.c, potentially allowing user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename. Other overflows, such as a heap-based overflow in the check idx function, might also exist but their exploitability is uncertain.
Recommendations For makeindex version 2.14 in teTeX, consider restricting the length of filenames to prevent potential buffer overflows until a patch is available. As a temporary workaround, avoid using long filenames with the open sty function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0650

Affected Products

Makeindex