Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-25262

Publication date 29 February 2024

Last updated 24 July 2024


Ubuntu priority

texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file.

Status

Package Ubuntu Release Status
texlive-bin 24.10 oracular
Not affected
24.04 LTS noble
Not affected
23.10 mantic
Fixed 2023.20230311.66589-6ubuntu0.1
22.04 LTS jammy
Fixed 2021.20210626.59705-1ubuntu0.2
20.04 LTS focal
Fixed 2019.20190605.51237-3ubuntu0.2
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty Ignored end of standard support

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
texlive-bin

References

Related Ubuntu Security Notices (USN)

    • USN-6695-1
    • TeX Live vulnerabilities
    • 14 March 2024

Other references