LaTeX2rtf Remote Buffer Overflow Vulnerability
BID:11233
Info
LaTeX2rtf Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11233 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2004 12:00AM |
| Updated: | Sep 21 2004 12:00AM |
| Credit: | D. J. Bernstein <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
LaTeX2rtf LaTeX2rtf 1.9.15 |
| Not Vulnerable: | |
Discussion
LaTeX2rtf Remote Buffer Overflow Vulnerability
It is reported that LaTeX2rtf is susceptible to a remote buffer overflow vulnerability when handling malformed files. This vulnerability may allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access. This issue is due to a failure of the application to perform proper bounds checks before copying data into a fixed sized memory buffer.
Version 1.9.15 of LaTeX2rtf is reported vulnerable to this issue. Other versions may also be affected.
It is reported that LaTeX2rtf is susceptible to a remote buffer overflow vulnerability when handling malformed files. This vulnerability may allow a remote attacker to execute arbitrary code on a vulnerable computer to gain unauthorized access. This issue is due to a failure of the application to perform proper bounds checks before copying data into a fixed sized memory buffer.
Version 1.9.15 of LaTeX2rtf is reported vulnerable to this issue. Other versions may also be affected.
Exploit / POC
LaTeX2rtf Remote Buffer Overflow Vulnerability
An exploit was provided:
An exploit was provided:
Solution / Fix
LaTeX2rtf Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
LaTeX2rtf Remote Buffer Overflow Vulnerability
References:
References:
- LaTeX2rtf Buffer Overflow Lets Remote Users Execute Arbitrary Code (SecurityTracker)
- LaTeX2rtf Home Page (LaTeX2rtf)