UBUNTU-CVE-2018-17407
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-17407
UBUNTU-CVE-2018-17407
Summary:
Details: An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex.
References: https://ubuntu.com/security/CVE-2018-17407, https://github.com/TeX-Live/texlive-source/commit/6ed0077520e2b0da1fd060c7f88db7b2e6068e4c, https://lists.debian.org/debian-security-announce/2018/msg00230.html, https://ubuntu.com/security/notices/USN-3788-1, https://ubuntu.com/security/notices/USN-3788-2, https://www.cve.org/CVERecord?id=CVE-2018-17407
Affected packages
Package
Name: texlive-bin
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
