This update for texlive fixes the following issue:
- CVE-2018-17407: Prevent buffer overflow when handling of Type 1 fonts
allowed arbitrary code execution when a malicious font was loaded by one
of the vulnerable tools: pdflatex, pdftex, dvips, or luatex (bsc#1109673)
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-1099=1
- openSUSE Leap 42.3 (i586 x86_64):
libkpathsea6-6.2.2-32.3.1
libkpathsea6-debuginfo-6.2.2-32.3.1
libptexenc1-1.3.4-32.3.1
libptexenc1-debuginfo-1.3.4-32.3.1
libsynctex1-1.18-32.3.1
libsynctex1-debuginfo-1.18-32.3.1
libtexlua52-5-5.2.4-32.3.1
libtexlua52-5-debuginfo-5.2.4-32.3.1
libtexluajit2-2.1.0beta2-32.3.1
libtexluajit2-debuginfo-2.1.0beta2-32.3.1
texlive-2016.20160523-32.3.1
texlive-a2ping-bin-2016.20160523.svn27321-32.3.1
texlive-accfonts-bin-2016.20160523.svn12688-32.3.1
texlive-adhocfilelist-bin-2016.20160523.svn28038-32.3.1
texlive-afm2pl-bin-2016.20160523.svn40473-32.3.1
texlive-afm2pl-bin-debuginfo-2016.20160523.svn40473-32.3.1
texlive-aleph-bin-2016.20160523.svn40987-32.3.1
texlive-aleph-bin-debuginfo-2016.20160523.svn40987-32.3.1
texlive-amstex-bin-2016.20160523.svn3006-32.3.1
texlive-arara-bin-2016.20160523.svn29036-32.3.1
texlive-asymptote-bin-2016.20160523.svn41076-32.3.1
texlive-asymptote-bin-debuginfo-2016.20160523.svn41076-32.3.1
texlive-authorindex-bin-2016.20160523.svn18790-32.3.1
texlive...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2018-17407.html
https://bugzilla.suse.com/1109673
--
Get the latest Linux and open source security news straight to your inbox.