The package latex2rtf before version 2.3.10-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201605-9 ======================================== Severity: High Date : 2016-05-06 CVE-ID : CVE-2015-8106 Package : latex2rtf Type : arbitrary code execution Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package latex2rtf before version 2.3.10-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 2.3.10-1. # pacman -Syu "latex2rtf> =2.3.10-1" The problem has been fixed upstream in version 2.3.10. Workaround ========= None. Description ========== A format string vulnerability was found in the CmdKeywords() function, where the user-controlled variable 'keywords' is passed as a format argument to vnsprintf(), when processing the \keywords command in a TeX file. Impact ===== An attacker can execute arbitrary code on the affected host by supplying a crafted TeX file. References ========= https://www.openwall.com/lists/oss-security/2015/11/16/39 https://access.redhat.com/security/cve/CVE-2015-8106 . Arch Linux Security Advisory ASA-202310-4 highlights a critical vulnerability in libxml2 that could facilitate unauthorized data access.. Arch Linux, latex2rtf, code execution threat, security advisory, updates. . LinuxSecurity.com Team
Update to 2.3.10 for CVE-2015-8106. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-b9368247d4 2016-04-09 10:22:58.046350 -------------------------------------------------------------------------------- Name : latex2rtf Product : Fedora 23 Version : 2.3.10 Release : 1.fc23 URL : Summary : LaTeX to RTF converter that handles equations, figures, and cross-references Description : LaTeX2rtf is a translator program which is intended to translate a LaTeX document (precisely: the text and a limited subset of LaTeX tags) into the RTF format which can be imported by several text processors (including Microsoft Word for Windows and Word for Macintosh). -------------------------------------------------------------------------------- Update Information: Update to 2.3.10 for CVE-2015-8106 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1282492 - CVE-2015-8106 latex2rtf: Format string vulnerability in CmdKeywords https://bugzilla.redhat.com/show_bug.cgi?id=1282492 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update latex2rtf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Update to 2.3.10 for CVE-2015-8106. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-246417376c 2016-04-08 19:41:16.227879 -------------------------------------------------------------------------------- Name : latex2rtf Product : Fedora 22 Version : 2.3.10 Release : 1.fc22 URL : Summary : LaTeX to RTF converter that handles equations, figures, and cross-references Description : LaTeX2rtf is a translator program which is intended to translate a LaTeX document (precisely: the text and a limited subset of LaTeX tags) into the RTF format which can be imported by several text processors (including Microsoft Word for Windows and Word for Macintosh). -------------------------------------------------------------------------------- Update Information: Update to 2.3.10 for CVE-2015-8106 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1282492 - CVE-2015-8106 latex2rtf: Format string vulnerability in CmdKeywords https://bugzilla.redhat.com/show_bug.cgi?id=1282492 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update latex2rtf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Update to 2.3.10 for CVE-2015-8106. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-3e320f369e 2016-04-05 10:09:11.083931 -------------------------------------------------------------------------------- Name : latex2rtf Product : Fedora 24 Version : 2.3.10 Release : 1.fc24 URL : Summary : LaTeX to RTF converter that handles equations, figures, and cross-references Description : LaTeX2rtf is a translator program which is intended to translate a LaTeX document (precisely: the text and a limited subset of LaTeX tags) into the RTF format which can be imported by several text processors (including Microsoft Word for Windows and Word for Macintosh). -------------------------------------------------------------------------------- Update Information: Update to 2.3.10 for CVE-2015-8106 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1282492 - CVE-2015-8106 latex2rtf: Format string vulnerability in CmdKeywords https://bugzilla.redhat.com/show_bug.cgi?id=1282492 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update latex2rtf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.