USN-9-1: tetex-bin vulnerabilities
Chris Evans and Marcus Meissner recently discovered several integer overflow vulnerabilities in xpdf, a viewer for PDF files. Because tetex-bin contains xpdf code, it is also affected. These vulnerabilities could be exploited by an attacker providing a specially crafted TeX, LaTeX, or PDF file. Processing such a file with pdflatex could result in abnormal program termination or the execution of program code supplied by the attacker. This bug could be exploited to gain the privileges of the user invoking pdflatex.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-9-1?
The severity of USN-9-1 is considered to be high due to the integer overflow vulnerabilities that could lead to exploitation.
How do I fix USN-9-1?
To fix USN-9-1, you should upgrade the tetex-bin package to the latest version available in your Ubuntu repositories.
Which versions of Ubuntu are affected by USN-9-1?
USN-9-1 affects Ubuntu version 4.10 and earlier due to the vulnerabilities present in the tetex-bin package.
What could an attacker do with the vulnerabilities in USN-9-1?
An attacker could exploit the vulnerabilities in USN-9-1 to execute arbitrary code by providing specially crafted input.
Are there any workarounds for USN-9-1?
There are no known workarounds for USN-9-1; the recommended action is to apply the provided patches or updates.