This update for texlive fixes the following issue:
- CVE-2018-17407: Prevent buffer overflow when handling of Type 1 fonts
allowed arbitrary code execution when a malicious font was loaded by one
of the vulnerable tools: pdflatex, pdftex, dvips, or luatex
(bsc#1109673).
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2018-1196=1
- openSUSE Leap 15.0 (i586 x86_64):
libkpathsea6-6.2.3-lp150.9.6.1
libkpathsea6-debuginfo-6.2.3-lp150.9.6.1
libptexenc1-1.3.5-lp150.9.6.1
libptexenc1-debuginfo-1.3.5-lp150.9.6.1
libsynctex1-1.18-lp150.9.6.1
libsynctex1-debuginfo-1.18-lp150.9.6.1
libtexlua52-5-5.2.4-lp150.9.6.1
libtexlua52-5-debuginfo-5.2.4-lp150.9.6.1
libtexluajit2-2.1.0beta2-lp150.9.6.1
libtexluajit2-debuginfo-2.1.0beta2-lp150.9.6.1
texlive-2017.20170520-lp150.9.6.1
texlive-a2ping-bin-2017.20170520.svn27321-lp150.9.6.1
texlive-accfonts-bin-2017.20170520.svn12688-lp150.9.6.1
texlive-adhocfilelist-bin-2017.20170520.svn28038-lp150.9.6.1
texlive-afm2pl-bin-2017.20170520.svn44143-lp150.9.6.1
texlive-afm2pl-bin-debuginfo-2017.20170520.svn44143-lp150.9.6.1
texlive-aleph-bin-2017.20170520.svn44143-lp150.9.6.1
texlive-aleph-bin-debuginfo-2017.20170520.svn44143-lp150.9.6.1
texlive-amstex-bin-2017.20170520.svn3006-lp150.9.6.1
texlive-arara-bin-2017.20170520.svn29036-lp150.9.6.1
texlive-asymptote-bin-2017.20170520.svn43843-lp150.9.6.1
texlive-asymptot...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2018-17407.html
https://bugzilla.suse.com/1109673
--
Get the latest Linux and open source security news straight to your inbox.