CVE-2018-17407
Summary
| CVE | CVE-2018-17407 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-23 21:29:00 UTC |
| Updated | 2018-11-15 16:11:00 UTC |
| Description | An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3788-1: Tex Live vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3788-2: Tex Live-bin vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] [DSA 4299-1] texlive-bin security update |
MISC |
lists.debian.org |
Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4299-1 texlive-bin |
DEBIAN |
www.debian.org |
Third Party Advisory |
| writet1 protection against buffer overflow · TeX-Live/texlive-source@6ed0077 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 351964 Amazon Linux Security Advisory for texlive: ALAS-2020-1388
- 375227 EulerOS Security Update for texlive (EulerOS-SA-2021-1368)
- 375347 EulerOS Security Update for texlive (EulerOS-SA-2020-2567)
- 375348 EulerOS Security Update for texlive (EulerOS-SA-2021-1126)
- 377313 Alibaba Cloud Linux Security Update for texlive (ALINUX2-SA-2020:0086)