Oval Definition:oval:com.redhat.rhsa:def:20050354
Revision Date:2005-04-01Version:502
Title:RHSA-2005:354: tetex security update (Moderate)
Description:TeTeX is an implementation of TeX for Linux or UNIX systems. TeX takes a text file and a set of formatting commands as input and creates a typesetter-independent .dvi (DeVice Independent) file as output.

A number of security flaws have been found affecting libraries used internally within teTeX. An attacker who has the ability to trick a user into processing a malicious file with teTeX could cause teTeX to crash or possibly execute arbitrary code.

A number of integer overflow bugs that affect Xpdf were discovered. The teTeX package contains a copy of the Xpdf code used for parsing PDF files and is therefore affected by these bugs. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0888 and CAN-2004-1125 to these issues.

A number of integer overflow bugs that affect libtiff were discovered. The teTeX package contains an internal copy of libtiff used for parsing TIFF image files and is therefore affected by these bugs. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0803, CAN-2004-0804 and CAN-2004-0886 to these issues.

Also latex2html is added to package tetex-latex for 64bit platforms.

Users of teTeX should upgrade to these updated packages, which contain backported patches and are not vulnerable to these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2004-0803
CVE-2004-0804
CVE-2004-0886
CVE-2004-0888
CVE-2004-1125
RHSA-2005:354-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND Package Information
  • tetex-xdvi is earlier than 0:1.0.7-67.7
  • AND tetex-xdvi is signed with Red Hat master key
  • OR
  • tetex is earlier than 0:1.0.7-67.7
  • AND tetex is signed with Red Hat master key
  • OR
  • tetex-fonts is earlier than 0:1.0.7-67.7
  • AND tetex-fonts is signed with Red Hat master key
  • OR
  • tetex-doc is earlier than 0:1.0.7-67.7
  • AND tetex-doc is signed with Red Hat master key
  • OR
  • tetex-latex is earlier than 0:1.0.7-67.7
  • AND tetex-latex is signed with Red Hat master key
  • OR
  • tetex-dvips is earlier than 0:1.0.7-67.7
  • AND tetex-dvips is signed with Red Hat master key
  • OR
  • tetex-afm is earlier than 0:1.0.7-67.7
  • AND tetex-afm is signed with Red Hat master key
  • BACK