|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2004-1293: rtf2latex2e buffer overflow in ReadFontTbl | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
| Component: | Incidents | Assignee: | Dr. Werner Fink <werner> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2004-1293: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: | 5.rtf | ||
|
Description
Marcus Meissner
2004-12-21 22:53:20 UTC
<!-- SBZ_reproduce --> see aboive Created attachment 27248 [details]
5.rtf
====================================================== Candidate: CAN-2004-1293 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1293 Reference: MISC:http://tigger.uic.edu/~jlongs2/holes/rtf2latex2e.txt Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file. Please could you give me a pointer to the package which includes rtf2latex2e or rtf2latex. I've found only a rtf2rtf and this is not owned by tetex. sorry, i just saw zgrep rtf2latex /mounts/dist/next-ppc/ARCHIVES.gz ./suse/ppc/tetex.rpm: -rw-r--r-- 1 root root 2431 Feb 6 2003 /usr/share/texmf/doc/help/Catalogue/entries/rtf2latex2e.html ignore this entry. CVE-2004-1293: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) |