Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Slackware 10.2: 2006:142-01 Critical: teTeX PDF Execution Risk

slackware
Calendar Grey May 22, 2006
Dist Slackware Esm H88
Recent updates for tetex packages in Slackware aimed at mitigating security vulnerabilities linked to PDF handling malfunctions.
New tetex packages are available for Slackware 10.2 and -current to fix a possible security issue

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/tetex-3.0-i486-2_10.2.tgz: Regenerated the etex.fmt files with etex, not pdfetex. This is more appropriate since etex is a binary, not a link to pdfetex. Thanks to John Breckenridge for reporting the issue. Added --disable-a4, and fixed the texconfig for US paper default in the build script. Thanks to Marc Benstein and Jingmin Zhou for reporting this. Improved /tmp use security. Patched a possible security issue in library code borrowed from xpdf that's used in pdfetex. For more information, see: https://www.cve.org/CVERecord?id=CVE-2005-3193 (* Security fix *)

Where Find New Packages

Updated package for Slackware 10.2: ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/tetex-3.0-i486-2_10.2.tgz
Updated packages for Slackware -current:

MD5 Signatures

Slackware 10.2 package: cdf43c3573e8235aa15bea3a6960a4e8 tetex-3.0-i486-2_10.2.tgz
Slackware -current packages: baae094f336ffc8a553328cc6d41d81a tetex-3.0-i486-2.tgz bf14a46df01c748b088b4b54010ddb98 tetex-doc-3.0-i486-2.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package(s) as root: # upgradepkg tetex-3.0-i486-2_10.2.tgz

Related News

Your message here