TeX Live: Multiple vulnerabilities — GLSA 201206-28

Multiple vulnerabilities were found in texlive-core, allowing attackers to execute arbitrary code.

Affected packages

app-text/texlive-core on all architectures
Affected versions < 2009-r2
Unaffected versions >= 2009-r2

Background

TeX Live is a complete TeX distribution.

Description

Multiple vulnerabilities have been discovered in texlive-core. Please review the CVE identifiers referenced below for details.

Impact

These vulnerabilities might allow user-assisted remote attackers to execute arbitrary code via a specially-crafted DVI file, or cause a Denial of Service.

Workaround

There is no known workaround at this time.

Resolution

All texlive-core users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-text/texlive-core-2009-r2"
 

References

Release date
June 25, 2012

Latest revision
June 25, 2012: 1

Severity
normal

Exploitable
remote

Bugzilla entries