First published: Fri Mar 12 2010(Updated: )
Dan Rosenberg found a buffer overflow flaw in the way TeX text formatting system processed virtual font files. If a user was tricked into processing a specially-crafted typesetter-independent .dvi (DeVice Independent) file, it could lead to dvips executable crash or, potentially, to arbitrary code execution with the privileges of the user running dvips.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tug Tex Live | =2007 | |
Tug Tex Live | =2008 | |
Tug Tex Live | =2004 | |
Tug Tex Live | <=2009 | |
Tug Tex Live | =2002 | |
Tug Tex Live | =1996 | |
Tug Tex Live | =2001 | |
Tug Tex Live | =1999 | |
Tug Tex Live | =2005 | |
Tug Tex Live | =1998 | |
Tug Tex Live | =2000 | |
Tug Tex Live | =2003 | |
Tug Tetex |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.