Oval Definition:oval:com.redhat.rhsa:def:20120137
Revision Date:2012-02-15Version:634
Title:RHSA-2012:0137: texlive security update (Moderate)
Description:TeX Live is an implementation of TeX. TeX takes a text file and a set of formatting commands as input, and creates a typesetter-independent DeVice Independent (DVI) file as output. The texlive packages provide a number of utilities, including dvips.

TeX Live embeds a copy of t1lib. The t1lib library allows you to rasterize bitmaps from PostScript Type 1 fonts. The following issues affect t1lib code:

  • Two heap-based buffer overflow flaws were found in the way t1lib processed Adobe Font Metrics (AFM) files. If a specially-crafted font file was opened by a TeX Live utility, it could cause the utility to crash or, potentially, execute arbitrary code with the privileges of the user running the utility. (CVE-2010-2642, CVE-2011-0433)

  • An invalid pointer dereference flaw was found in t1lib. A specially-crafted font file could, when opened, cause a TeX Live utility to crash or, potentially, execute arbitrary code with the privileges of the user running the utility. (CVE-2011-0764)

  • A use-after-free flaw was found in t1lib. A specially-crafted font file could, when opened, cause a TeX Live utility to crash or, potentially, execute arbitrary code with the privileges of the user running the utility. (CVE-2011-1553)

  • An off-by-one flaw was found in t1lib. A specially-crafted font file could, when opened, cause a TeX Live utility to crash or, potentially, execute arbitrary code with the privileges of the user running the utility. (CVE-2011-1554)

  • An out-of-bounds memory read flaw was found in t1lib. A specially-crafted font file could, when opened, cause a TeX Live utility to crash. (CVE-2011-1552)

    Red Hat would like to thank the Evince development team for reporting CVE-2010-2642. Upstream acknowledges Jon Larimer of IBM X-Force as the original reporter of CVE-2010-2642.

    All users of texlive are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-2642
    CVE-2010-2642
    CVE-2011-0433
    CVE-2011-0433
    CVE-2011-0764
    CVE-2011-0764
    CVE-2011-1552
    CVE-2011-1552
    CVE-2011-1553
    CVE-2011-1553
    CVE-2011-1554
    CVE-2011-1554
    RHSA-2012:0137
    RHSA-2012:0137-01
    RHSA-2012:0137-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • kpathsea is earlier than 0:2007-57.el6_2
  • AND kpathsea is signed with Red Hat redhatrelease2 key
  • kpathsea-devel is earlier than 0:2007-57.el6_2
  • AND kpathsea-devel is signed with Red Hat redhatrelease2 key
  • mendexk is earlier than 0:2.6e-57.el6_2
  • AND mendexk is signed with Red Hat redhatrelease2 key
  • texlive is earlier than 0:2007-57.el6_2
  • AND texlive is signed with Red Hat redhatrelease2 key
  • texlive-afm is earlier than 0:2007-57.el6_2
  • AND texlive-afm is signed with Red Hat redhatrelease2 key
  • texlive-context is earlier than 0:2007-57.el6_2
  • AND texlive-context is signed with Red Hat redhatrelease2 key
  • texlive-dvips is earlier than 0:2007-57.el6_2
  • AND texlive-dvips is signed with Red Hat redhatrelease2 key
  • texlive-dviutils is earlier than 0:2007-57.el6_2
  • AND texlive-dviutils is signed with Red Hat redhatrelease2 key
  • texlive-east-asian is earlier than 0:2007-57.el6_2
  • AND texlive-east-asian is signed with Red Hat redhatrelease2 key
  • texlive-latex is earlier than 0:2007-57.el6_2
  • AND texlive-latex is signed with Red Hat redhatrelease2 key
  • texlive-utils is earlier than 0:2007-57.el6_2
  • AND texlive-utils is signed with Red Hat redhatrelease2 key
  • texlive-xetex is earlier than 0:2007-57.el6_2
  • AND texlive-xetex is signed with Red Hat redhatrelease2 key
  • BACK