Bug#409709: CVE-2007-0650 tetex-bin: Buffer overflows in teTeX's makeindex

2007-02-04 Thread Frank Küster
Alex de Oliveira Silva <[EMAIL PROTECTED]> wrote: > close 409709 > thanks > > Only affected if compiled w/o kpathsea support. > Thanks Moritz Muehlenhoff. Indeed, I've already discussed this with Moritz. Do you have an idea why Fedora disables kpathsea support? That looks like a very strange r

Bug#409709: CVE-2007-0650 tetex-bin: Buffer overflows in teTeX's makeindex

2007-02-04 Thread Alex de Oliveira Silva
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 close 409709 thanks Only affected if compiled w/o kpathsea support. Thanks Moritz Muehlenhoff. regards, - -- .''`. : :' :Alex de Oliveira Silva | enerv `. `' www.enerv.net `- -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.6 (

Bug#409709: CVE-2007-0650 tetex-bin: Buffer overflows in teTeX's makeindex

2007-02-04 Thread Alex de Oliveira Silva
Package: tetex-bin Version: 3.0-29 Severity: important Tags: security Hi. Discovered one Buffer overflow in the open_sty function in mkind.c for makeindex 2.14 might allow user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename. Referente: https:/