Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian DSA 207-1 Critical: Remote Command Execution In Tetex-Bin

debian
Calendar Grey December 11, 2002
Debian Logo
A critical Debian advisory reports a remote command execution issue in tetex-bin. Immediate updates are recommended for users.
xdvi and dvips call thesystem() function insecurely, which allows a remote attacker toexecute arbitrary commands via cleverly crafted DVI files.

Summary

The SuSE security team discovered a vulnerability in kpathsea library
(libkpathsea) which is used by xdvi and dvips. Both programs call the
system() function insecurely, which allows a remote attacker to
execute arbitrary commands via cleverly crafted DVI files.

If dvips is used in a print filter, this allows a local or remote
attacker with print permission execute arbitrary code as the printer
user (usually lp).

This problem has been fixed in version 1.0.7+20011202-7.1for the
current stable distribution (woody), in version 1.0.6-7.3 for the old
stable distribution (potato) and in version 1.0.7+20021025-4 for the
unstable distribution (sid). xdvik-ja and dvipsk-ja are vulnerable as
well, but link to the kpathsea library dynamically and will
automatically be fixed after a new libkpathsea is installed.

We recommend that you upgrade your tetex-lib package immediately.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get pa...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: tetex-bin

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here