Lucene search

K
redhatRedHatRHSA-2005:026
HistoryMar 16, 2005 - 12:00 a.m.

(RHSA-2005:026) tetex security update

2005-03-1600:00:00
access.redhat.com
14

0.096 Low

EPSS

Percentile

94.8%

The tetex packages (teTeX) contain an implementation of TeX for Linux or
UNIX systems.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects teTeX due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause teTeX to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects teTeX due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause teTeX to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.

Users should update to these erratum packages which contain backported
patches to correct these issues.