Vulnerability Bulletins |
Múltiples vulnerabilidades en teTeX y TeXlive |
|
Vulnerability classification |
|
Property | Value |
Confidence level | Oficial |
Impact | Obtener acceso |
Dificulty | Experto |
Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
Property | Value |
Affected manufacturer | GNU/Linux |
Affected software |
teTeX TeXlive <= 2007 dvips dviljk |
Description |
|
Se han encontrado múltiples vulnerabilidades en teTeX y en TeXlive en la versión 2007 y anteriores. Las vulnerabilidades son descritas a continuación. - CVE-2007-5935: Se ha encontrado una vulnerabilidad del tipo desbordamiento de búfer en teTeX y en TeXlive en la versión 2007 y anteriores. La vulnerabilidad reside en un error en dvips en el archivo hpc.c. Un atacante remoto podría ejecutar código arbitrario mediante un archivo DVI con una gran etiqueta href. - CVE-2007-5936: Se ha encontrado una vulnerabilidad en teTeX y en TeXlive en la versión 2007 y anteriores. La vulnerabilidad reside en un error en dvips. Un atacante local podría obtener información sensible y modificar ciertos datos mediante crear determinados archivos temporales antes de que sean procesados por dviljk. - CVE-2007-5937: Se han encontrado múltiples vulnerabilidades del tipo desbordamiento de búfer en teTeX y en TeXlive en la versión 2007 y anteriores. Las vulnerabilidades residen en un error en dviljk. Un atacante remoto podría ejecutar código arbitrario mediante un archivo de entrada DVI especialmente diseñado. |
|
Solution |
|
Actualización de software Mandriva (MDKSA-2007:230) Mandriva Linux 2007 X86 ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/jadetex-3.12-116.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-afm-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-context-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-devel-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-doc-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-dvilj-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-dvipdfm-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-dvips-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-latex-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-mfwin-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-texi2html-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/tetex-xdvi-3.0-18.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/i586/media/main/updates/xmltex-1.9-64.5mdv2007.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/SRPMS/main/updates/tetex-3.0-18.5mdv2007.0.src.rpm X86_64 ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/jadetex-3.12-116.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-afm-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-context-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-devel-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-doc-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-dvilj-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-dvipdfm-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-dvips-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-latex-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-mfwin-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-texi2html-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/tetex-xdvi-3.0-18.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/x86_64/media/main/updates/xmltex-1.9-64.5mdv2007.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.0/SRPMS/main/updates/tetex-3.0-18.5mdv2007.0.src.rpm Corporate Server 4.0 X86 corporate/4.0/i586/jadetex-3.12-110.6.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-afm-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-context-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-devel-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-doc-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-dvilj-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-dvipdfm-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-dvips-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-latex-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-mfwin-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-texi2html-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/tetex-xdvi-3.0-12.7.20060mlcs4.i586.rpm corporate/4.0/i586/xmltex-1.9-58.6.20060mlcs4.i586.rpm corporate/4.0/SRPMS/tetex-3.0-12.7.20060mlcs4.src.rpm X86_64 corporate/4.0/x86_64/jadetex-3.12-110.6.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-afm-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-context-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-devel-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-doc-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-dvilj-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-dvipdfm-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-dvips-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-latex-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-mfwin-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-texi2html-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/tetex-xdvi-3.0-12.7.20060mlcs4.x86_64.rpm corporate/4.0/x86_64/xmltex-1.9-58.6.20060mlcs4.x86_64.rpm corporate/4.0/SRPMS/tetex-3.0-12.7.20060mlcs4.src.rpm Mandriva Linux 2007.1 X86 ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/jadetex-3.12-129.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-afm-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-context-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-devel-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-doc-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-dvilj-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-dvipdfm-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-dvips-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-latex-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-mfwin-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-texi2html-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-usrlocal-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/tetex-xdvi-3.0-31.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/i586/media/main/updates/xmltex-1.9-77.4mdv2007.1.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/SRPMS/main/updates/tetex-3.0-31.4mdv2007.1.src.rpm X86_64 ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/jadetex-3.12-129.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-afm-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-context-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-devel-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-doc-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-dvilj-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-dvipdfm-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-dvips-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-latex-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-mfwin-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-texi2html-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-usrlocal-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/tetex-xdvi-3.0-31.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/x86_64/media/main/updates/xmltex-1.9-77.4mdv2007.1.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2007.1/SRPMS/main/updates/tetex-3.0-31.4mdv2007.1.src.rpm Mandriva Linux 2008.0 X86 ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/jadetex-3.12-136.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-afm-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-context-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-devel-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-doc-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-dvilj-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-dvipdfm-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-dvips-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-latex-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-mfwin-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-texi2html-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-usrlocal-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/tetex-xdvi-3.0-38.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/i586/media/main/updates/xmltex-1.9-84.1mdv2008.0.i586.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/SRPMS/main/updates/tetex-3.0-38.1mdv2008.0.src.rpm X86_64 ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/jadetex-3.12-136.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-afm-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-context-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-devel-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-doc-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-dvilj-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-dvipdfm-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-dvips-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-latex-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-mfwin-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-texi2html-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-usrlocal-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/tetex-xdvi-3.0-38.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/x86_64/media/main/updates/xmltex-1.9-84.1mdv2008.0.x86_64.rpm ftp://ftp.cica.es/pub/Linux/Mandrakelinux/official/updates/2008.0/SRPMS/main/updates/tetex-3.0-38.1mdv2008.0.src.rpm Suse Linux Las actualizaciones pueden descargarse mediante YAST o del servidor FTP oficial de Suse Linux. Red Hat (RHSA-2010:0401-1) Red Hat Desktop (v. 3) Red Hat Enterprise Linux AS (v. 3) Red Hat Enterprise Linux ES (v. 3) Red Hat Enterprise Linux WS (v. 3) https://rhn.redhat.com/ Red Hat (RHSA-2010:0399-1) Red Hat Desktop (v. 4) Red Hat Enterprise Linux AS (v. 4) Red Hat Enterprise Linux AS (v. 4.8.z) Red Hat Enterprise Linux ES (v. 4) Red Hat Enterprise Linux ES (v. 4.8.z) Red Hat Enterprise Linux WS (v. 4) https://rhn.redhat.com/ |
|
Standar resources |
|
Property | Value |
CVE |
CVE-2007-5935 CVE-2007-5936 CVE-2007-5937 |
BID | 26469 |
Other resources |
|
Mandriva Security Advisory (MDKSA-2007:230) http://www.mandriva.com/security/advisories?name=MDKSA-2007:230 SUSE Security Advisory (SUSE-SR:2008:001) http://www.novell.com/linux/security/advisories/suse_security_announce_62.html Red Hat Security Advisory (RHSA-2010:0401-1) https://rhn.redhat.com/errata/RHSA-2010-0401.html Red Hat Security Advisory (RHSA-2010:0399-1) https://rhn.redhat.com/errata/RHSA-2010-0399.html |
Version history |
||
Version | Comments | Date |
1.0 | Aviso emitido | 2007-11-23 |
1.1 | Aviso emitido por Suse (SUSE-SR:2008:001) | 2008-01-23 |
1.2 | Aviso emitido por Red Hat (RHSA-2010:0401-1) | 2010-05-07 |