drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in Tex (Aktualisierung)
Name: |
Ausführen beliebiger Kommandos in Tex (Aktualisierung) |
|
ID: |
USN-3788-2 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 18.10 |
|
Datum: |
Di, 23. Oktober 2018, 15:28 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17407 |
|
Applikationen: |
TeX Live |
|
Update von: |
Zwei Probleme in Tex |
|
Originalnachricht |
--===============4965075657132057003== Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="=-LPCJHgFS3tDpLyDWEPyu"
--=-LPCJHgFS3tDpLyDWEPyu Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-3788-2 October 23, 2018
texlive-bin vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.10
Summary:
Several security issues were fixed in Tex Live.
Software Description: - texlive-bin: TeX Live: path search library for TeX (development part)
Details:
USN-3788-1 fixed vulnerabilities in Tex Live. This update provides the corresponding update for Ubuntu 18.10
Original advisory details:
It was discovered that Tex Live incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-17407)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.10: texlive-binaries 2018.20180824.48463-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References: https://usn.ubuntu.com/usn/usn-3788-2 https://usn.ubuntu.com/usn/usn-3788-1 CVE-2018-17407
Package Information: https://launchpad.net/ubuntu/+source/texlive-bin/2018.20180824.48463-1ubuntu0.1 --=-LPCJHgFS3tDpLyDWEPyu Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2
iQIcBAABCAAGBQJbzxHLAAoJEEW851uECx9pRdwP/250mYb411IMwCjGqi0wgDyN TperJt9P0c1noF5utCK7IhAM0XmgtepiPcc4xxeoCtgvkmEEu2b12oXUFPNVghT5 dGPaYqYduBjgv+TJAQuasX2/Zw0q8NvdTw8zRxRGta6xm13p2UHh/NrousYmYgVv qxIwsH97jdQx3Sx2bJMUpdc8mWkt5ay+qlKgZg8fUvzadi0IiJsjjUb8rC8vbKjV oBSHzXwSo/FWDZ7NBbHG6c73sGwHwC91vWx5CiTzBsziCXHRStIbDKh7uzNzZMxN VHKVho6PJC9euobym7n+MmiAa1u6MmjT32S3WZ8Tw+JJnWD+NZlE0jTdD98xAHHa REldjIo77Xs2A9x4A5SneESzu53fkkNx3Dds7wkWNCXTaw31N/PA3J/GVfzsiLLm MGzloTUg6dgYqwYeo6KR5RQRGarXWgTwK+3G9y+rPhmrFjZEGE/hYXlqVL96juRa o8nLJGs1U605E22U0Nh65ima+GYqk5kF4K7nrflzTYPN09t9VYV+Q7so66kAlBXi zU0JCZRFJlkd1NY6gJsoowevWf49ABZwiVV6UXGN7TCg87d6N67Fnm+46/hcyUKe RbiziZgsDB/9d95ud++bJVgXy0x44Dl7uOahKhHzyTXe0e0pdArB7rqxcjAKVrUh pBcoeQvOTzLvPLkXjstj =egc0 -----END PGP SIGNATURE-----
--=-LPCJHgFS3tDpLyDWEPyu--
--===============4965075657132057003== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK
--===============4965075657132057003==--
|
|
|
|