teTeX DVI File Parsing Multiple Vulnerabilities
BID:26469
Info
teTeX DVI File Parsing Multiple Vulnerabilities
| Bugtraq ID: | 26469 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-5936 CVE-2007-5935 CVE-2007-5937 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 28 2007 12:00AM |
| Updated: | Mar 19 2015 09:03AM |
| Credit: | Bastien Roucaries and Joachim Schrod are credited with the discovery of these issues. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Tex Live TeX Live 2007 teTeX teTeX 3.0 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE openSUSE 10.3 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop version 4 RedHat Desktop 3.0 Red Hat Fedora 7 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 pTeX pTeX 3.1.10 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux 2007.0 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha CSTeX cstetex 2.0.2 |
| Not Vulnerable: | |
Discussion
teTeX DVI File Parsing Multiple Vulnerabilities
teTeX is prone to multiple vulnerabilities that include buffer-overflow errors and race-condition issues.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application, cause denial-of-service conditions, or obtain potentially sensitive information.
teTeX is prone to multiple vulnerabilities that include buffer-overflow errors and race-condition issues.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application, cause denial-of-service conditions, or obtain potentially sensitive information.
Exploit / POC
teTeX DVI File Parsing Multiple Vulnerabilities
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
teTeX DVI File Parsing Multiple Vulnerabilities
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
References
teTeX DVI File Parsing Multiple Vulnerabilities
References:
References:
- Debian Bug report logs - #447081: dvips -z segfault with really long url on \hre (Debian)
- dviljk ChangeLog (Gentoo)
- teTeX Homepage (teTeX)