PT-2024-5166 · Tex Live+3 · Texlive-Bin+3
Attackoncs
+1
·
Published
2024-02-20
·
Updated
2026-04-25
·
CVE-2024-25262
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
texlive-bin version c515e
Description:
The issue is related to a heap buffer overflow in the
ttfLoadHDMX:ttfdump function of the texlive-bin component in TeX Live computer typesetting systems. This allows attackers to cause a Denial of Service (DoS) by supplying a crafted TTF file. The vulnerability can be exploited by a remote attacker to disrupt service.Recommendations:
For texlive-bin version c515e, consider disabling the
ttfLoadHDMX:ttfdump function as a temporary workaround until a patch is available to prevent potential Denial of Service attacks.Fix
DoS
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Ubuntu
Texlive-Bin