Re: [security] TeXLive CVE-2018-17407

2018-10-10 Thread Jeremie Courreges-Anglas
Woops, I missed MAINTAINER in ../Makefile.inc On Wed, Oct 10 2018, Jeremie Courreges-Anglas wrote: > "An issue was discovered in t1_check_unusual_charstring functions in > writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the > handling of Type 1 fonts allows arbitrary code ex

[security] TeXLive CVE-2018-17407

2018-10-10 Thread Jeremie Courreges-Anglas
"An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex."