Oval Definition:oval:com.redhat.rhsa:def:20100401
Revision Date:2010-05-06Version:640
Title:RHSA-2010:0401: tetex security update (Moderate)
Description:teTeX is an implementation of TeX. TeX takes a text file and a set of formatting commands as input, and creates a typesetter-independent DeVice Independent (DVI) file as output.

  • A buffer overflow flaw was found in the way teTeX processed virtual font files when converting DVI files into PostScript. An attacker could create a malicious DVI file that would cause the dvips executable to crash or, potentially, execute arbitrary code. (CVE-2010-0827)

  • Multiple integer overflow flaws were found in the way teTeX processed special commands when converting DVI files into PostScript. An attacker could create a malicious DVI file that would cause the dvips executable to crash or, potentially, execute arbitrary code. (CVE-2010-0739, CVE-2010-1440)

  • A stack-based buffer overflow flaw was found in the way teTeX processed DVI files containing HyperTeX references with long titles, when converting them into PostScript. An attacker could create a malicious DVI file that would cause the dvips executable to crash. (CVE-2007-5935)

    teTeX embeds a copy of Xpdf, an open source Portable Document Format (PDF) file viewer, to allow adding images in PDF format to the generated PDF documents. The following issues affect Xpdf code:

  • Multiple integer overflow flaws were found in Xpdf. If a local user generated a PDF file from a TeX document, referencing a specially-crafted PDF file, it would cause Xpdf to crash or, potentially, execute arbitrary code with the privileges of the user running pdflatex. (CVE-2009-0791, CVE-2009-3609)

    All users of tetex are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-5935
    CVE-2009-0791
    CVE-2009-3609
    CVE-2010-0739
    CVE-2010-0827
    CVE-2010-1440
    RHSA-2010:0401
    RHSA-2010:0401-01
    RHSA-2010:0401-01
    Platform(s):Red Hat Enterprise Linux 3
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • tetex-xdvi is earlier than 0:1.0.7-67.19
  • AND tetex-xdvi is signed with Red Hat master key
  • tetex-fonts is earlier than 0:1.0.7-67.19
  • AND tetex-fonts is signed with Red Hat master key
  • tetex-dvips is earlier than 0:1.0.7-67.19
  • AND tetex-dvips is signed with Red Hat master key
  • tetex is earlier than 0:1.0.7-67.19
  • AND tetex is signed with Red Hat master key
  • tetex-afm is earlier than 0:1.0.7-67.19
  • AND tetex-afm is signed with Red Hat master key
  • tetex-latex is earlier than 0:1.0.7-67.19
  • AND tetex-latex is signed with Red Hat master key
  • BACK