drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in TeX Live
Name: |
Ausführen beliebiger Kommandos in TeX Live |
|
ID: |
DSA-3803-1 |
|
Distribution: |
Debian |
|
Plattformen: |
Debian sid, Debian jessie |
|
Datum: |
Mi, 8. März 2017, 10:42 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10243 |
|
Applikationen: |
TeX Live |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
- ------------------------------------------------------------------------- Debian Security Advisory DSA-3803-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 08, 2017 https://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : texlive-base CVE ID : CVE-2016-10243
It was discovered that texlive-base, the TeX Live package which provides the essential TeX programs and files, whitelists mpost as an external program to be run from within the TeX source code (called \write18). Since mpost allows to specify other programs to be run, an attacker can take advantage of this flaw for arbitrary code execution when compiling a TeX document.
For the stable distribution (jessie), this problem has been fixed in version 2014.20141024-2+deb8u1.
For the upcoming stable distribution (stretch), this problem has been fixed in version 2016.20161130-1.
For the unstable distribution (sid), this problem has been fixed in version 2016.20161130-1.
We recommend that you upgrade your texlive-base packages.
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAli/mWpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0R17w//RlU8Gq7SWalB2+arW4eOvoFwAnBVA89NGt1BgUddDIuFJ0a1Ze0cfxFu s0Fskfi4gBAnyj4gwIIEY/d5lgnuO3vubiB01G5dhgxBDDk1TFVbfdclm1w4Y6Sv WPszm9iA8NhfNB3/fizijQTdLP0knCtjSLZB1d7ntaWycxyZuLifHOMYxJdljvmG geADgNB6cXvHvQbwgqO7LGqs6q2i8Ar0wPiVJuya8LYrvqHMze6vvBEch/ijhQqc 7eG37fl8AWiM+oNNhnrPdueP8U0SGXZ/MlRSKt3XmzhJCUtWhsXVjxGcFVg+YvW5 tEIDnjFr0hxwVWKMtp9aCh25adrIQzEbSCgNiGDgU4smFN2/uqenq4KBBfrKWFN/ hESyBkweU2aITM5RLvud5lowJEGMziV7p//5bEA9NwjBFxUJUf6lt3viX3bBs9jb j7rg9oorJ1MLyjh8amfpCtqh0lp2uRnAyoXegvvvhmF2NnyLY5T059nuuoWuqxvQ OPX887hmMLOxS+evY7kGGVcn4vRHv5PKiVhDdI+LQY0qQtE7iF3z5UGXQof1MO5a Kw/SZZDXSDJJ8LMWyUcdUoO8pq0JQcGYnJTkuV4GaeDzF0PuMNlwX08CylM/e51E tbwtSHsR/K6U1EOh3Lck105AiN7VANCsTsbqTvldDiqAdW/p+Mw= =ltds -----END PGP SIGNATURE-----
|
|
|
|