PT-2011-1029 · Tex Live+4 · Texlive-Debuginfo+15

Huzaifa S. Sidhpurwala

+1

·

Published

2011-01-06

·

Updated

2024-06-15

·

CVE-2010-2642

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions texlive-debuginfo-2007 versions 2007 texlive-dviutils-2007 versions 2007 texlive-context-2007 versions 2007 texlive-utils-2007 versions 2007 texlive-2007 versions 2007 t1lib versions 5.1.2 and earlier texlive-dvips-2007 versions 2007 texlive-xetex-2007 versions 2007 mendexk-2.6e versions 2.6e texlive-afm-2007 versions 2007 kpathsea-2007 versions 2007 kpathsea-devel-2007 versions 2007 texlive-east-asian-2007 versions 2007 texlive-latex-2007 versions 2007
Description The issue is related to multiple vulnerabilities in various packages of the texlive and t1lib software, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A heap-based buffer overflow in the AFM font parser in the dvi-backend component allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted font in conjunction with a DVI file.
Recommendations For texlive-debuginfo-2007 version 2007, update to a newer version. For texlive-dviutils-2007 version 2007, update to a newer version. For texlive-context-2007 version 2007, update to a newer version. For texlive-utils-2007 version 2007, update to a newer version. For texlive-2007 version 2007, update to a newer version. For t1lib version 5.1.2 and earlier, update to a newer version. For texlive-dvips-2007 version 2007, update to a newer version. For texlive-xetex-2007 version 2007, update to a newer version. For mendexk-2.6e version 2.6e, update to a newer version. For texlive-afm-2007 version 2007, update to a newer version. For kpathsea-2007 version 2007, update to a newer version. For kpathsea-devel-2007 version 2007, update to a newer version. For texlive-east-asian-2007 version 2007, update to a newer version. For texlive-latex-2007 version 2007, update to a newer version. As a temporary workaround, consider disabling the AFM font parser in the dvi-backend component until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3095
ALT-PU-2020-3114
ALT-PU-2022-1925
AZL-37047
AZL-7376
BDU:2015-02170
BDU:2015-06275
BDU:2015-06276
BDU:2015-06417
BDU:2015-06563
BDU:2015-06564
BDU:2015-06565
BDU:2015-06566
BDU:2015-06567
BDU:2015-06568
BDU:2015-06569
BDU:2015-06570
BDU:2015-06571
BDU:2015-06572
BDU:2015-08613
BDU:2015-08614
BDU:2015-08615
BDU:2015-08616
BDU:2015-08617
BDU:2015-08618
BDU:2015-08619
BDU:2015-08620
BDU:2015-08621
BDU:2015-08622
CESA-2012_0062
CESA-2012_0137
CVE-2010-2642
DSA-2357-1
DSA-2388-1
OPENSUSE-SU-2024:10041-1
RHSA-2011:0009
RHSA-2011_0009
RHSA-2012:0062
RHSA-2012:0137
RHSA-2012:1201
RHSA-2012_0062
RHSA-2012_0137
RHSA-2012_1201

Affected Products

Alt Linux
Centos
Red Hat
Kpathsea
Kpathsea-Devel
T1Lib
Tex Live
Texlive-Afm
Texlive-Context
Texlive-Debuginfo
Texlive-Dvips
Texlive-Dviutils
Texlive-East-Asian
Texlive-Latex
Texlive-Utils
Texlive-Xetex