An issue was discovered in t1checkunusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "libkpathsea-dev", "binary_version": "2013.20130729.30972-2ubuntu0.1" }, { "binary_name": "libkpathsea6", "binary_version": "2013.20130729.30972-2ubuntu0.1" }, { "binary_name": "libkpathsea6-dbgsym", "binary_version": "2013.20130729.30972-2ubuntu0.1" }, { "binary_name": "libptexenc-dev", "binary_version": "2013.20130729.30972-2ubuntu0.1" }, { "binary_name": "libptexenc1", "binary_version": "2013.20130729.30972-2ubuntu0.1" }, { "binary_name": "libptexenc1-dbgsym", "binary_version": "2013.20130729.30972-2ubuntu0.1" }, { "binary_name": "texlive-binaries", "binary_version": "2013.20130729.30972-2ubuntu0.1" }, { "binary_name": "texlive-binaries-dbgsym", "binary_version": "2013.20130729.30972-2ubuntu0.1" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "libkpathsea-dev", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libkpathsea6", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libkpathsea6-dbgsym", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libptexenc-dev", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libptexenc1", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libptexenc1-dbgsym", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libsynctex-dev", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libsynctex1", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libsynctex1-dbgsym", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libtexlua52", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libtexlua52-dbgsym", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libtexlua52-dev", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libtexluajit-dev", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libtexluajit2", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "libtexluajit2-dbgsym", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "texlive-binaries", "binary_version": "2015.20160222.37495-1ubuntu0.1" }, { "binary_name": "texlive-binaries-dbgsym", "binary_version": "2015.20160222.37495-1ubuntu0.1" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "libkpathsea-dev", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libkpathsea6", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libkpathsea6-dbgsym", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libptexenc-dev", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libptexenc1", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libptexenc1-dbgsym", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libsynctex-dev", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libsynctex1", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libsynctex1-dbgsym", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libtexlua52", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libtexlua52-dbgsym", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libtexlua52-dev", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libtexluajit-dev", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libtexluajit2", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "libtexluajit2-dbgsym", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "texlive-binaries", "binary_version": "2017.20170613.44572-8ubuntu0.1" }, { "binary_name": "texlive-binaries-dbgsym", "binary_version": "2017.20170613.44572-8ubuntu0.1" } ] }