Multiple vulnerabilities have been found in the GNU texinfo package, a documentation system for on-line information and printed output. CVE-2005-3011: Handling of temporary files is performed in an insecure manner, allowing an attacker to overwrite any file writable by the victim. CVE-2006-4810: A buffer overflow in util/texindex.c could allow an attacker to execute arbitrary code with the victim's access rights by inducing the victim to run texindex or tex2dvi on a specially crafted texinfo file.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1219-1
Texinfo is vulnerable to a buffer overflow that could lead to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200611-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Texinfo: Buffer overflow Date: November 21, 2006 Bugs: #154316 ID: 200611-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Texinfo is vulnerable to a buffer overflow that could lead to the execution of arbitrary code. Background ========= Texinfo is the official documentation system of the GNU project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/texinfo < 4.8-r5 > = 4.8-r5 Description ========== Miloslav Trmac from Red Hat discovered a buffer overflow in the "readline()" function of texindex.c. The "readline()" function is called by the texi2dvi and texindex commands. Impact ===== By enticing a user to open a specially crafted Texinfo file, an attacker could execute arbitrary code with the rights of the user running Texinfo. Workaround ========= There is no known workaround at this time. Resolution ========= All Texinfo users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-apps/texinfo-4.8-r5" References ========= [ 1 ] CVE-2006-4810 https://www.cve.org/CVERecord?id=CVE-2006-4810 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200611-16 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Miloslav Trmac discovered a buffer overflow in texinfo's index processor. If a user is tricked into processing a .texi file with texindex, this could lead to arbitrary code execution with user privileges. . =========================================================== Ubuntu Security Notice USN-379-1 November 09, 2006 texinfo vulnerability CVE-2006-4810 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: texinfo 4.7-2.2ubuntu2.2 Ubuntu 6.06 LTS: texinfo 4.8-4ubuntu0.1 Ubuntu 6.10: texinfo 4.8.dfsg.1-1ubuntu0.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Miloslav Trmac discovered a buffer overflow in texinfo's index processor. If a user is tricked into processing a .texi file with texindex, this could lead to arbitrary code execution with user privileges. Updated packages for Ubuntu 5.10: Source archives: Size/MD5: 11833 dbf91981a497afa47113442ce4ed0533 Size/MD5: 628 480efa82cf08b6963a177bb604e0371e Size/MD5: 1979183 72a57e378efb9898c9e41ca839554dae amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 192672 f51581a20b86f59af743f9547548c954 Size/MD5: 493882 a0b44c7e6a7e480a83ed408bb6800534 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 177692 2613c823cba8d7708ef57fe4077d5db8 Size/MD5: 473330 01b7874093bcff3bdaa7d21230436e09 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 191208 5d82f615d46977241c4a3e6522198401 Size/MD5: 48596404f7d4dc025281ca7bb7ff540cdf1a9c sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 181058 37f778e57466fb9877aa811e8cd94b5b Size/MD5: 481292 2d54253517e006ee699b8e16d6a1ea25 Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 19252 ee6ac44a36a7ed2e8cc47e1c2c284da5 Size/MD5: 633 0c2b881a99eb3ad4339fc50950972b61 Size/MD5: 2140626 4e9a1a591ed236003d0d4b008bf07eef amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 229240 86e76ba873bd62de9af444c19e57ad3a Size/MD5: 852588 1d838a30c689d19a73ce03c317c4f70c i386 architecture (x86 compatible Intel/AMD) Size/MD5: 214256 1cf7872794bde31aabb86c46fe391efd Size/MD5: 829570 aee0c9143502a4a5e4f9e609efcab148 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 227110 15865da8beaed2861f16d6b2cc2256b2 Size/MD5: 843556 48bf74169ae31bd35ca88d0ac848ca34 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 217200 47affbbec4b08430599eaeb4165ae655 Size/MD5: 836036 41e7f10f98c1c8b9785a9e1554cc5eee Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 100133 b8aa5026ba781447623b5dca13c16adf Size/MD5: 655 6186cfa19347067109a79dc335e45e67 Size/MD5: 1926534 614273ac8568a25926aae374cd9a6683 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 176152 129a8486cff04779d1ea839ca0246eb9 Size/MD5: 318218 ec83d76fe3ed49d3941b7b2429e6aaf9 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 163446 1cb94cd6cd61a08fe57cbf760330fdda Size/MD5: 298598 2df120b6e3cccbf5d4981bbccc438778 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 174196 01cf7f495443794e667b2039bdc3a0aa Size/MD5: 310246 30b317a623898ecfdaf3e96b603816ba sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 164286 a3c0ed9ca8d975f4780b891122b259ee Size/MD5: 302436 d47dfb713bc7aa13d75c95e2dfe04073 . Important security advisory about texinfo flaw with potential buffer overflow threats for code execution affecting Ubuntu users.. texinfo Fix, Ubuntu Advisory, Code Execution Alert, Security Patch, Buffer Overflow Issue. . Severity: Critical. LinuxSecurity.com Team
New Texinfo packages that fix various security . Date: Wed, 8 Nov 2006 16:51:42 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "texinfo" on SL 301,302,303,304,305,307,308 i386,x86_64 now available Comments: To:
New Texinfo packages that fix various security . Date: Wed, 8 Nov 2006 16:13:00 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "texinfo" on SL 40,41,42,43,44 i386,x86_64 now available Comments: To:
New Texinfo packages that fix various security vulnerabilities are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: texinfo security update Advisory ID: RHSA-2006:0727-01 Advisory URL: https://access.redhat.com/errata/RHSA-2006:0727.html Issue date: 2006-11-08 Updated on: 2006-11-08 Product: Red Hat Enterprise Linux CVE Names: CVE-2005-3011 CVE-2006-4810 - ---------------------------------------------------------------------1. Summary: New Texinfo packages that fix various security vulnerabilities are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: Texinfo is a documentation system that can produce both online information and printed output from a single source file. A buffer overflow flaw was found in Texinfo's texindex command. An attacker could construct a carefully crafted Texinfo file that could cause texindex to crash or possibly execute arbitrary code when opened. (CVE-2006-4810) A flawwas found in the way Texinfo's texindex command creates temporary files. A local user could leverage this flaw to overwrite files the user executing texindex has write access to. (CVE-2005-3011) Users of Texinfo should upgrade to these updated packages which contain backported patches and are not vulnerable to these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 169583 - CVE-2005-3011 texindex insecure temporary file usage 170743 - CVE-2005-3011 texindex insecure temporary file usage 170744 - CVE-2005-3011 texindex insecure temporary file usage 211484 - CVE-2006-4810 texindex buffer overflow 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 4f77dc80717cf15b1f565cb8dfb12b8c texinfo-4.0b-3.el2.1.src.rpm i386: 878a207e614180cf8fd43920d51947d6 info-4.0b-3.el2.1.i386.rpm 58cc2bc691496d3aef522fc87449554b texinfo-4.0b-3.el2.1.i386.rpm ia64: a259d8d26dbaa8cc96686f169dc05911 info-4.0b-3.el2.1.ia64.rpm 6fae56c8168b45be80ae719ebe0aca82 texinfo-4.0b-3.el2.1.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 4f77dc80717cf15b1f565cb8dfb12b8c texinfo-4.0b-3.el2.1.src.rpm ia64: a259d8d26dbaa8cc96686f169dc05911 info-4.0b-3.el2.1.ia64.rpm 6fae56c8168b45be80ae719ebe0aca82 texinfo-4.0b-3.el2.1.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 4f77dc80717cf15b1f565cb8dfb12b8c texinfo-4.0b-3.el2.1.src.rpm i386: 878a207e614180cf8fd43920d51947d6 info-4.0b-3.el2.1.i386.rpm 58cc2bc691496d3aef522fc87449554b texinfo-4.0b-3.el2.1.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 4f77dc80717cf15b1f565cb8dfb12b8c texinfo-4.0b-3.el2.1.src.rpm i386: 878a207e614180cf8fd43920d51947d6 info-4.0b-3.el2.1.i386.rpm 58cc2bc691496d3aef522fc87449554b texinfo-4.0b-3.el2.1.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: cae389223d777d79c862b4672c75a9e1 texinfo-4.5-3.el3.1.src.rpm i386: 1fc65ec7fb762b72f4f31030e10a8bba info-4.5-3.el3.1.i386.rpm 04bd5020018f6727b77fd8c2a9fb2588 texinfo-4.5-3.el3.1.i386.rpm 1ee197caad9a5c8fa930215a7c5ca9e6 texinfo-debuginfo-4.5-3.el3.1.i386.rpm ia64: 42ca02702693284272a52b61b0914d66 info-4.5-3.el3.1.ia64.rpm 3fabad46614f61118bc29cffbd83df54 texinfo-4.5-3.el3.1.ia64.rpm d8bb2bd2fd7be72a8822e93b1372b625 texinfo-debuginfo-4.5-3.el3.1.ia64.rpm ppc: 5fe3e1eca608678fc0770f0de702cd8d info-4.5-3.el3.1.ppc.rpm 9275ad56b995b25f275af0a44c3d01bf texinfo-4.5-3.el3.1.ppc.rpm f54a3f00a87b3ce1d4d0af73f0601bf7 texinfo-debuginfo-4.5-3.el3.1.ppc.rpm s390: 215d4ea1202a2309c7c676e3c1e46299 info-4.5-3.el3.1.s390.rpm 7085ead3927535c315c336c3314b9d2f texinfo-4.5-3.el3.1.s390.rpm 2d670e1ec1d3ab67628aa982d125bed4 texinfo-debuginfo-4.5-3.el3.1.s390.rpm s390x: fd6332f0b59ad9bd8f99cf40a8ff1ad9 info-4.5-3.el3.1.s390x.rpm a7d61c3643d31ac0db2f6b15d0ea996b texinfo-4.5-3.el3.1.s390x.rpm 566c653544cdb5e1a5eb82f6b67edb9c texinfo-debuginfo-4.5-3.el3.1.s390x.rpm x86_64: 544245c16b5f0d94a65c9c9ccb4c94cc info-4.5-3.el3.1.x86_64.rpm 8921c67695089cf7d6fb4bc7fe61c24a texinfo-4.5-3.el3.1.x86_64.rpm 5e7e98da194c722cee0ab2e1f05989b8 texinfo-debuginfo-4.5-3.el3.1.x86_64.rpm Red Hat Desktop version 3: SRPMS: cae389223d777d79c862b4672c75a9e1 texinfo-4.5-3.el3.1.src.rpm i386: 1fc65ec7fb762b72f4f31030e10a8bba info-4.5-3.el3.1.i386.rpm 04bd5020018f6727b77fd8c2a9fb2588 texinfo-4.5-3.el3.1.i386.rpm 1ee197caad9a5c8fa930215a7c5ca9e6 texinfo-debuginfo-4.5-3.el3.1.i386.rpm x86_64: 544245c16b5f0d94a65c9c9ccb4c94cc info-4.5-3.el3.1.x86_64.rpm 8921c67695089cf7d6fb4bc7fe61c24a texinfo-4.5-3.el3.1.x86_64.rpm 5e7e98da194c722cee0ab2e1f05989b8 texinfo-debuginfo-4.5-3.el3.1.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: cae389223d777d79c862b4672c75a9e1 texinfo-4.5-3.el3.1.src.rpm i386: 1fc65ec7fb762b72f4f31030e10a8bba info-4.5-3.el3.1.i386.rpm 04bd5020018f6727b77fd8c2a9fb2588 texinfo-4.5-3.el3.1.i386.rpm 1ee197caad9a5c8fa930215a7c5ca9e6 texinfo-debuginfo-4.5-3.el3.1.i386.rpm ia64: 42ca02702693284272a52b61b0914d66 info-4.5-3.el3.1.ia64.rpm 3fabad46614f61118bc29cffbd83df54 texinfo-4.5-3.el3.1.ia64.rpm d8bb2bd2fd7be72a8822e93b1372b625 texinfo-debuginfo-4.5-3.el3.1.ia64.rpm x86_64: 544245c16b5f0d94a65c9c9ccb4c94cc info-4.5-3.el3.1.x86_64.rpm 8921c67695089cf7d6fb4bc7fe61c24a texinfo-4.5-3.el3.1.x86_64.rpm 5e7e98da194c722cee0ab2e1f05989b8 texinfo-debuginfo-4.5-3.el3.1.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: cae389223d777d79c862b4672c75a9e1 texinfo-4.5-3.el3.1.src.rpm i386: 1fc65ec7fb762b72f4f31030e10a8bba info-4.5-3.el3.1.i386.rpm 04bd5020018f6727b77fd8c2a9fb2588 texinfo-4.5-3.el3.1.i386.rpm 1ee197caad9a5c8fa930215a7c5ca9e6 texinfo-debuginfo-4.5-3.el3.1.i386.rpm ia64: 42ca02702693284272a52b61b0914d66 info-4.5-3.el3.1.ia64.rpm 3fabad46614f61118bc29cffbd83df54 texinfo-4.5-3.el3.1.ia64.rpm d8bb2bd2fd7be72a8822e93b1372b625 texinfo-debuginfo-4.5-3.el3.1.ia64.rpm x86_64: 544245c16b5f0d94a65c9c9ccb4c94cc info-4.5-3.el3.1.x86_64.rpm 8921c67695089cf7d6fb4bc7fe61c24a texinfo-4.5-3.el3.1.x86_64.rpm 5e7e98da194c722cee0ab2e1f05989b8 texinfo-debuginfo-4.5-3.el3.1.x86_64.rpm Red Hat Enterprise Linux AS version 4: SRPMS: c5fabea21ca9dbc20658e542dabf2922 texinfo-4.7-5.el4.2.src.rpm i386: 7e86f2eef9fb548f6be88025bee5a9b6 info-4.7-5.el4.2.i386.rpm 5f509002c109ce1a2b9876b60e7b1eee texinfo-4.7-5.el4.2.i386.rpm 11151582bace0b111ec2061041da9a01 texinfo-debuginfo-4.7-5.el4.2.i386.rpm ia64: 99deee5e7579a4d49a0c7cb82a13e54b info-4.7-5.el4.2.ia64.rpm 119c541a6cfe685fc2762e4718c772de texinfo-4.7-5.el4.2.ia64.rpm 17d075dc8887246a394f9bb699791d81 texinfo-debuginfo-4.7-5.el4.2.ia64.rpm ppc: 706a14c171a272ce82f3201364ec17a2 info-4.7-5.el4.2.ppc.rpm 1d1b035106a9889fa3bfa96f79a88248 texinfo-4.7-5.el4.2.ppc.rpm 52cc1d3e4c5fa6f2d745654706363d22 texinfo-debuginfo-4.7-5.el4.2.ppc.rpm s390: 1f1c0056ceed97e903f70f9583bce14a info-4.7-5.el4.2.s390.rpm d4170f862521f47487a88eae5f1c6946 texinfo-4.7-5.el4.2.s390.rpm 6eb45ee9e2bcf48289334e33c3b54846 texinfo-debuginfo-4.7-5.el4.2.s390.rpm s390x: f5ccba218def5a9c496ff4ff6a8177d2 info-4.7-5.el4.2.s390x.rpm bd3f9d50bb9855b8adeefe44ca7c0793 texinfo-4.7-5.el4.2.s390x.rpm d64aa22173ce1036c50a23748f835251 texinfo-debuginfo-4.7-5.el4.2.s390x.rpm x86_64: 8211780e84883ff3c9f5428a54cadfcd info-4.7-5.el4.2.x86_64.rpm 33ec657749738e6737a569d75ffe79c3 texinfo-4.7-5.el4.2.x86_64.rpm d824601958b4d0b0961f5ea9c312bd9e texinfo-debuginfo-4.7-5.el4.2.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: c5fabea21ca9dbc20658e542dabf2922 texinfo-4.7-5.el4.2.src.rpm i386: 7e86f2eef9fb548f6be88025bee5a9b6 info-4.7-5.el4.2.i386.rpm 5f509002c109ce1a2b9876b60e7b1eee texinfo-4.7-5.el4.2.i386.rpm 11151582bace0b111ec2061041da9a01 texinfo-debuginfo-4.7-5.el4.2.i386.rpm x86_64: 8211780e84883ff3c9f5428a54cadfcd info-4.7-5.el4.2.x86_64.rpm 33ec657749738e6737a569d75ffe79c3 texinfo-4.7-5.el4.2.x86_64.rpm d824601958b4d0b0961f5ea9c312bd9e texinfo-debuginfo-4.7-5.el4.2.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: c5fabea21ca9dbc20658e542dabf2922 texinfo-4.7-5.el4.2.src.rpm i386: 7e86f2eef9fb548f6be88025bee5a9b6 info-4.7-5.el4.2.i386.rpm 5f509002c109ce1a2b9876b60e7b1eee texinfo-4.7-5.el4.2.i386.rpm 11151582bace0b111ec2061041da9a01 texinfo-debuginfo-4.7-5.el4.2.i386.rpm ia64: 99deee5e7579a4d49a0c7cb82a13e54b info-4.7-5.el4.2.ia64.rpm 119c541a6cfe685fc2762e4718c772de texinfo-4.7-5.el4.2.ia64.rpm 17d075dc8887246a394f9bb699791d81 texinfo-debuginfo-4.7-5.el4.2.ia64.rpm x86_64: 8211780e84883ff3c9f5428a54cadfcd info-4.7-5.el4.2.x86_64.rpm 33ec657749738e6737a569d75ffe79c3 texinfo-4.7-5.el4.2.x86_64.rpm d824601958b4d0b0961f5ea9c312bd9e texinfo-debuginfo-4.7-5.el4.2.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: c5fabea21ca9dbc20658e542dabf2922 texinfo-4.7-5.el4.2.src.rpm i386: 7e86f2eef9fb548f6be88025bee5a9b6 info-4.7-5.el4.2.i386.rpm 5f509002c109ce1a2b9876b60e7b1eee texinfo-4.7-5.el4.2.i386.rpm 11151582bace0b111ec2061041da9a01 texinfo-debuginfo-4.7-5.el4.2.i386.rpm ia64: 99deee5e7579a4d49a0c7cb82a13e54b info-4.7-5.el4.2.ia64.rpm 119c541a6cfe685fc2762e4718c772de texinfo-4.7-5.el4.2.ia64.rpm 17d075dc8887246a394f9bb699791d81 texinfo-debuginfo-4.7-5.el4.2.ia64.rpm x86_64: 8211780e84883ff3c9f5428a54cadfcd info-4.7-5.el4.2.x86_64.rpm 33ec657749738e6737a569d75ffe79c3 texinfo-4.7-5.el4.2.x86_64.rpm d824601958b4d0b0961f5ea9c312bd9e texinfo-debuginfo-4.7-5.el4.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2005-3011 https://www.cve.org/CVERecord?id=CVE-2006-4810 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2006 Red Hat, Inc. . The latest update for the Texinfo package addresses significant security issues found in Red Hat environments.. Red Hat Security Update, Texinfo Issues, Linux Update, Buffer Overflow, File Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.