CVE-2007-5935

Publication date 13 November 2007

Last updated 24 July 2024


Ubuntu priority

Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code via a DVI file with a long href tag.

Read the notes from the security team

Status

Package Ubuntu Release Status
tetex-bin 8.04 LTS hardy Not in release
7.10 gutsy Not in release
7.04 feisty
Fixed 3.0-27ubuntu1.2
6.10 edgy
Fixed 3.0-17ubuntu2.1
6.06 LTS dapper
Fixed 3.0-13ubuntu6.1
texlive-bin 8.04 LTS hardy
Not affected
7.10 gutsy
Fixed 2007-12ubuntu3.1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Not in release

Notes


jdstrand

fixed in hardy with Debian's hps-segfault-fix

References

Related Ubuntu Security Notices (USN)

    • USN-554-1
    • teTeX and TeX Live vulnerabilities
    • 6 December 2007

Other references