QID 351964

Date Published: 2021-05-26

QID 351964: Amazon Linux Security Advisory for texlive: ALAS-2020-1388

An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex. (CVE-2018-17407 )

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Please refer to Amazon advisory ALAS-2020-1388 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 351964

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2020-1388 Amazon Linux texlive (svn26912.0-45.20130427_r30134.amzn1) on i686 URL Logo alas.aws.amazon.com/ALAS-2020-1388.html
    ALAS-2020-1388 Amazon Linux texlive (svn26912.0-45.20130427_r30134.amzn1) on noarch URL Logo alas.aws.amazon.com/ALAS-2020-1388.html
    ALAS-2020-1388 Amazon Linux texlive (svn26912.0-45.20130427_r30134.amzn1) on src URL Logo alas.aws.amazon.com/ALAS-2020-1388.html
    ALAS-2020-1388 Amazon Linux texlive (svn26912.0-45.20130427_r30134.amzn1) on x86_64 URL Logo alas.aws.amazon.com/ALAS-2020-1388.html