PT-2011-1030 · Tex Live+5 · Texlive-Debuginfo+16

Jan Lieskovsky

·

Published

2011-01-07

·

Updated

2022-05-23

·

CVE-2011-0433

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions texlive-debuginfo-2007 version 2007 texlive-dviutils-2007 version 2007 texlive-context-2007 version 2007 texlive-utils-2007 version 2007 texlive-2007 version 2007 t1lib (affected versions not specified) texlive-xetex-2007 version 2007 mendexk-2.6e version 2.6e texlive-dvips-2007 version 2007 texlive-latex-2007 version 2007 texlive-afm-2007 version 2007 kpathsea-2007 version 2007 kpathsea-devel-2007 version 2007 texlive-east-asian-2007 version 2007
Description The issue is related to multiple vulnerabilities in various packages of the texlive and t1lib software, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A heap-based buffer overflow in the linetoken function in afmparse.c in t1lib allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics file.
Recommendations For texlive-debuginfo-2007 version 2007, update to a newer version. For texlive-dviutils-2007 version 2007, update to a newer version. For texlive-context-2007 version 2007, update to a newer version. For texlive-utils-2007 version 2007, update to a newer version. For texlive-2007 version 2007, update to a newer version. For t1lib, update to a newer version. For texlive-xetex-2007 version 2007, update to a newer version. For mendexk-2.6e version 2.6e, update to a newer version. For texlive-dvips-2007 version 2007, update to a newer version. For texlive-latex-2007 version 2007, update to a newer version. For texlive-afm-2007 version 2007, update to a newer version. For kpathsea-2007 version 2007, update to a newer version. For kpathsea-devel-2007 version 2007, update to a newer version. For texlive-east-asian-2007 version 2007, update to a newer version. As a temporary workaround, consider disabling the vulnerable functions until a patch is available. Restrict access to the vulnerable modules to minimize the risk of exploitation. Avoid using the vulnerable parameters in the affected API endpoints until the issue is resolved.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3095
ALT-PU-2020-3114
ALT-PU-2022-1925
AZL-37048
AZL-7377
BDU:2015-02170
BDU:2015-06275
BDU:2015-06276
BDU:2015-06417
BDU:2015-06563
BDU:2015-06564
BDU:2015-06565
BDU:2015-06566
BDU:2015-06567
BDU:2015-06568
BDU:2015-06569
BDU:2015-06570
BDU:2015-06571
BDU:2015-06572
BDU:2015-08613
BDU:2015-08614
BDU:2015-08615
BDU:2015-08616
BDU:2015-08617
BDU:2015-08618
BDU:2015-08619
BDU:2015-08620
BDU:2015-08621
BDU:2015-08622
CESA-2012_0062
CESA-2012_0137
CVE-2011-0433
DSA-2388-1
RHSA-2012:0062
RHSA-2012:0137
RHSA-2012:1201
RHSA-2012_0062
RHSA-2012_0137
RHSA-2012_1201
SUSE-SU-2012_0744-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Kpathsea
Kpathsea-Devel
T1Lib
Tex Live
Texlive-Afm
Texlive-Context
Texlive-Debuginfo
Texlive-Dvips
Texlive-Dviutils
Texlive-East-Asian
Texlive-Latex
Texlive-Utils
Texlive-Xetex