Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE: 2018:3213-1 Important: Texlive Buffer Overflow Risk

opensuse
Calendar Grey October 18, 2018
Dist Opensuse Esm H88
An important update for openSUSE Leap has been released to fix high-level vulnerabilities in texlive, ensuring your system remains secure and current
An update that fixes one vulnerability is now available.

Description

This update for texlive fixes the following issue:

- CVE-2018-17407: Prevent buffer overflow when handling of Type 1 fonts

allowed arbitrary code execution when a malicious font was loaded by one

of the vulnerable tools: pdflatex, pdftex, dvips, or luatex

(bsc#1109673).

This update was imported from the SUSE:SLE-15:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-1196=1

Package List

- openSUSE Leap 15.0 (i586 x86_64):

libkpathsea6-6.2.3-lp150.9.6.1

libkpathsea6-debuginfo-6.2.3-lp150.9.6.1

libptexenc1-1.3.5-lp150.9.6.1

libptexenc1-debuginfo-1.3.5-lp150.9.6.1

libsynctex1-1.18-lp150.9.6.1

libsynctex1-debuginfo-1.18-lp150.9.6.1

libtexlua52-5-5.2.4-lp150.9.6.1

libtexlua52-5-debuginfo-5.2.4-lp150.9.6.1

libtexluajit2-2.1.0beta2-lp150.9.6.1

libtexluajit2-debuginfo-2.1.0beta2-lp150.9.6.1

texlive-2017.20170520-lp150.9.6.1

texlive-a2ping-bin-2017.20170520.svn27321-lp150.9.6.1

texlive-accfonts-bin-2017.20170520.svn12688-lp150.9.6.1

texlive-adhocfilelist-bin-2017.20170520.svn28038-lp150.9.6.1

texlive-afm2pl-bin-2017.20170520.svn44143-lp150.9.6.1

texlive-afm2pl-bin-debuginfo-2017.20170520.svn44143-lp150.9.6.1

texlive-aleph-bin-2017.20170520.svn44143-lp150.9.6.1

texlive-aleph-bin-debuginfo-2017.20170520.svn44143-lp150.9.6.1

texlive-amstex-bin-2017.20170520.svn3006-lp150.9.6.1

texlive-arara-bin-2017.20170520.svn29036-lp150.9.6.1

texlive-asymptote-bin-2017.20170520.svn43843-lp150.9.6.1

texlive-asymptot...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-17407.html

https://bugzilla.suse.com/1109673

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:3213-1
Rating: important
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here