Hide Forgot
Marc Schoenefeld found an integer overflow in the way TeX text formatting system processed special commands. If a user was tricked into processing a specially-crafted typesetter-independent .dvi (DeVice Independent) file, it could lead to dvips executable crash or, potentially, to arbitrary code execution with the privileges of the user running dvips.
This issue affects the versions of the tetex package, as shipped with Red Hat Enterprise Linux 3, 4, and 5. This issue affects the versions of the texlive package, as shipped with Fedora release of 11 and 12.
Created attachment 399653 [details] Patch to fix the integer allocation overflow Patch like this should handle this overflow. Please review.
This is CVE-2010-0739.
Created attachment 401680 [details] Updated patch from Karl Berry
Public via: [1] http://git.frugalware.org/gitweb/gitweb.cgi?p=frugalware-stable.git;a=blob;f=source/xapps-extra/tetex/texlive-CVE-2010-0739-int-overflow.patch
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Via RHSA-2010:0399 https://rhn.redhat.com/errata/RHSA-2010-0399.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2010:0400 https://rhn.redhat.com/errata/RHSA-2010-0400.html
This issue has been addressed in following products: Red Hat Enterprise Linux 3 Via RHSA-2010:0401 https://rhn.redhat.com/errata/RHSA-2010-0401.html
Original upstream commit for this issue is: http://www.tug.org/svn/texlive?view=revision&revision=17559 Subsequent patch r18095 is needed to address related CVE-2010-1440 too: https://bugzilla.redhat.com/show_bug.cgi?id=586819#c13
texlive-2007-47.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/texlive-2007-47.fc11
texlive-2007-48.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/texlive-2007-48.fc12
texlive-2007-51.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/texlive-2007-51.fc13
texlive-2007-51.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.
texlive-2007-48.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.
texlive-2007-47.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.