Back Linuxsecurity Ubuntu 22.04 TeX Live Important DOS Network Attacks USN-7985
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in TeX Live. Software Description: - texlive-bin: Binaries for TeX Live Details: Shin Ando discovered that the Xpdf toolkit embedded in TeX Live incorrectly handled memory when decoding certain data streams. An attacker could possibly use this issue to cause TeX Live to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24106, CVE-2022-24107) It was discovered that TeX Live allowed documents to make arbitrary network requests. If a user or automated system were tricked into opening a specially crafted document, a remote attacker could possibly use this issue to exfiltrate sensitive information, or perform other network-related attacks. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in TeX Live. Software Description: - texlive-bin: Binaries for TeX Live Details: Shin Ando discovered that the Xpdf toolkit embedded in TeX Live incorrectly handled memory when decoding certain data streams. An attacker could possibly use this issue to cause TeX Live to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24106, CVE-2022-24107) It was discovered that TeX Live allowed documents to make arbitrary network requests. If a user or automated system were tricked into opening a specially crafted document, a remote attacker could possibly use this issue to exfiltrate sensitive information, or perform other network-related attacks. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS texlive-binaries 2021.20210626.59705-1ubuntu0.3 Ubuntu 20.04 LTS texlive-binaries 2019.20190605.51237-3ubuntu0.2+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS texlive-binaries 2017.20170613.44572-8ubuntu0.2+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS texlive-binaries 2015.20160222.37495-1ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS texlive-binaries 2021.20210626.59705-1ubuntu0.3 Ubuntu 20.04 LTS texlive-binaries 2019.20190605.51237-3ubuntu0.2+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS texlive-binaries 2017.20170613.44572-8ubuntu0.2+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS texlive-binaries 2015.20160222.37495-1ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
CVE-2022-24106, CVE-2022-24107, CVE-2023-32668, CVE-2024-25262
CVE-2022-24106, CVE-2022-24107, CVE-2023-32668, CVE-2024-25262
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
