Debian DLA-1514-1 : texlive-bin security update

high Nessus Plugin ID 117641

Synopsis

The remote Debian host is missing a security update.

Description

Nick Roessler from the University of Pennsylvania has found a buffer overflow in texlive-bin, the executables for TexLive, the popular distribution of TeX document production system.

This buffer overflow can be used for arbitrary code execution by crafting a special type1 font (.pfb) and provide it to users running pdf(la)tex, dvips or luatex in a way that the font is loaded.

For Debian 8 'Jessie', this problem has been fixed in version 2014.20140926.35254-6+deb8u1.

We recommend that you upgrade your texlive-bin packages.

NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Upgrade the affected packages.

See Also

https://lists.debian.org/debian-lts-announce/2018/09/msg00025.html

https://packages.debian.org/source/jessie/texlive-bin

Plugin Details

Severity: High

ID: 117641

File Name: debian_DLA-1514.nasl

Version: 1.3

Type: local

Agent: unix

Published: 9/24/2018

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:libkpathsea-dev, p-cpe:/a:debian:debian_linux:libkpathsea6, p-cpe:/a:debian:debian_linux:libptexenc-dev, p-cpe:/a:debian:debian_linux:libptexenc1, p-cpe:/a:debian:debian_linux:libsynctex-dev, p-cpe:/a:debian:debian_linux:libsynctex1, p-cpe:/a:debian:debian_linux:luatex, p-cpe:/a:debian:debian_linux:texlive-binaries, cpe:/o:debian:debian_linux:8.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 9/21/2018