CVE-2018-17407

An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
tugtex_live
𝑥
< 2018-09-21
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
18.10
debiandebian_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
texlive-bin
bookworm
2022.20220321.62855-5.1+deb12u1
fixed
bullseye
2020.20200327.54578-7+deb11u1
fixed
bullseye (security)
2020.20200327.54578-7+deb11u2
fixed
sid
2024.20240313.70630+ds-5
fixed
trixie
2024.20240313.70630+ds-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
texlive-bin
bionic
Fixed 2017.20170613.44572-8ubuntu0.1
released
cosmic
Fixed 2018.20180824.48463-1ubuntu0.1
released
trusty
Fixed 2013.20130729.30972-2ubuntu0.1
released
xenial
Fixed 2015.20160222.37495-1ubuntu0.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libkpathsea6
suse enterprise desktop 15
6.2.3-11.8.4
fixed
suse enterprise desktop 15 SP1
6.2.3-11.8.4
fixed
suse enterprise desktop 15 SP2
6.2.3-19.4
fixed
suse enterprise desktop 15 SP3
6.2.3-19.4
fixed
suse enterprise desktop 15 SP4
6.3.3-150400.29.15
fixed
suse enterprise desktop 15 SP5
6.3.3-150400.29.15
fixed
suse enterprise desktop 15 SP6
6.3.3-150600.36.10
fixed
suse enterprise desktop 15 SP7
6.3.3-150600.36.10
fixed
suse enterprise sap 15
6.2.3-11.8.4
fixed
suse enterprise sap 15 SP1
6.2.3-11.8.4
fixed
suse enterprise sap 15 SP2
6.2.3-19.4
fixed
suse enterprise sap 15 SP3
6.2.3-19.4
fixed
suse enterprise sap 15 SP4
6.3.3-150400.29.15
fixed
suse enterprise sap 15 SP5
6.3.3-150400.29.15
fixed
suse enterprise sap 15 SP6
6.3.3-150600.36.10
fixed
suse enterprise sap 15 SP7
6.3.3-150600.36.10
fixed
suse enterprise server 15
6.2.3-11.8.4
fixed
suse enterprise server 15 SP1
6.2.3-11.8.4
fixed
suse enterprise server 15 SP2
6.2.3-19.4
fixed
suse enterprise server 15 SP3
6.2.3-19.4
fixed
suse enterprise server 15 SP4
6.3.3-150400.29.15
fixed
suse enterprise server 15 SP5
6.3.3-150400.29.15
fixed
suse enterprise server 15 SP6
6.3.3-150600.36.10
fixed
suse enterprise server 15 SP7
6.3.3-150600.36.10
fixed
libptexenc1
suse enterprise desktop 15
1.3.5-11.8.4
fixed
suse enterprise desktop 15 SP1
1.3.5-11.8.4
fixed
suse enterprise desktop 15 SP2
1.3.5-19.4
fixed
suse enterprise desktop 15 SP3
1.3.5-19.4
fixed
suse enterprise desktop 15 SP4
1.3.9-150400.29.15
fixed
suse enterprise desktop 15 SP5
1.3.9-150400.29.15
fixed
suse enterprise desktop 15 SP6
1.3.9-150600.36.10
fixed
suse enterprise desktop 15 SP7
1.3.9-150600.36.10
fixed
suse enterprise sap 15
1.3.5-11.8.4
fixed
suse enterprise sap 15 SP1
1.3.5-11.8.4
fixed
suse enterprise sap 15 SP2
1.3.5-19.4
fixed
suse enterprise sap 15 SP3
1.3.5-19.4
fixed
suse enterprise sap 15 SP4
1.3.9-150400.29.15
fixed
suse enterprise sap 15 SP5
1.3.9-150400.29.15
fixed
suse enterprise sap 15 SP6
1.3.9-150600.36.10
fixed
suse enterprise sap 15 SP7
1.3.9-150600.36.10
fixed
suse enterprise server 15
1.3.5-11.8.4
fixed
suse enterprise server 15 SP1
1.3.5-11.8.4
fixed
suse enterprise server 15 SP2
1.3.5-19.4
fixed
suse enterprise server 15 SP3
1.3.5-19.4
fixed
suse enterprise server 15 SP4
1.3.9-150400.29.15
fixed
suse enterprise server 15 SP5
1.3.9-150400.29.15
fixed
suse enterprise server 15 SP6
1.3.9-150600.36.10
fixed
suse enterprise server 15 SP7
1.3.9-150600.36.10
fixed
libsynctex1
suse enterprise desktop 15
1.18-11.8.4
fixed
suse enterprise desktop 15 SP1
1.18-11.8.4
fixed
suse enterprise desktop 15 SP2
1.18-19.4
fixed
suse enterprise desktop 15 SP3
1.18-19.4
fixed
suse enterprise sap 15
1.18-11.8.4
fixed
suse enterprise sap 15 SP1
1.18-11.8.4
fixed
suse enterprise sap 15 SP2
1.18-19.4
fixed
suse enterprise sap 15 SP3
1.18-19.4
fixed
suse enterprise server 15
1.18-11.8.4
fixed
suse enterprise server 15 SP1
1.18-11.8.4
fixed
suse enterprise server 15 SP2
1.18-19.4
fixed
suse enterprise server 15 SP3
1.18-19.4
fixed
libsynctex2
suse enterprise desktop 15 SP4
1.21-150400.29.15
fixed
suse enterprise desktop 15 SP5
1.21-150400.29.15
fixed
suse enterprise desktop 15 SP6
1.21-150600.36.10
fixed
suse enterprise desktop 15 SP7
1.21-150600.36.10
fixed
suse enterprise sap 15 SP4
1.21-150400.29.15
fixed
suse enterprise sap 15 SP5
1.21-150400.29.15
fixed
suse enterprise sap 15 SP6
1.21-150600.36.10
fixed
suse enterprise sap 15 SP7
1.21-150600.36.10
fixed
suse enterprise server 15 SP4
1.21-150400.29.15
fixed
suse enterprise server 15 SP5
1.21-150400.29.15
fixed
suse enterprise server 15 SP6
1.21-150600.36.10
fixed
suse enterprise server 15 SP7
1.21-150600.36.10
fixed
libtexlua52-5
suse enterprise desktop 15
5.2.4-11.8.4
fixed
suse enterprise desktop 15 SP1
5.2.4-11.8.4
fixed
suse enterprise desktop 15 SP2
5.2.4-19.4
fixed
suse enterprise desktop 15 SP3
5.2.4-19.4
fixed
suse enterprise sap 15
5.2.4-11.8.4
fixed
suse enterprise sap 15 SP1
5.2.4-11.8.4
fixed
suse enterprise sap 15 SP2
5.2.4-19.4
fixed
suse enterprise sap 15 SP3
5.2.4-19.4
fixed
suse enterprise server 15
5.2.4-11.8.4
fixed
suse enterprise server 15 SP1
5.2.4-11.8.4
fixed
suse enterprise server 15 SP2
5.2.4-19.4
fixed
suse enterprise server 15 SP3
5.2.4-19.4
fixed
libtexlua53-5
suse enterprise desktop 15 SP4
5.3.6-150400.29.15
fixed
suse enterprise desktop 15 SP5
5.3.6-150400.29.15
fixed
suse enterprise desktop 15 SP6
5.3.6-150600.36.10
fixed
suse enterprise desktop 15 SP7
5.3.6-150600.36.10
fixed
suse enterprise sap 15 SP4
5.3.6-150400.29.15
fixed
suse enterprise sap 15 SP5
5.3.6-150400.29.15
fixed
suse enterprise sap 15 SP6
5.3.6-150600.36.10
fixed
suse enterprise sap 15 SP7
5.3.6-150600.36.10
fixed
suse enterprise server 15 SP4
5.3.6-150400.29.15
fixed
suse enterprise server 15 SP5
5.3.6-150400.29.15
fixed
suse enterprise server 15 SP6
5.3.6-150600.36.10
fixed
suse enterprise server 15 SP7
5.3.6-150600.36.10
fixed
texlive
suse enterprise desktop 15
2017.20170520-11.8.4
fixed
suse enterprise desktop 15 SP1
2017.20170520-11.8.4
fixed
suse enterprise desktop 15 SP2
2017.20170520-19.4
fixed
suse enterprise desktop 15 SP3
2017.20170520-19.4
fixed
suse enterprise desktop 15 SP4
2021.20210325-150400.29.15
fixed
suse enterprise desktop 15 SP5
2021.20210325-150400.29.15
fixed
suse enterprise desktop 15 SP6
2021.20210325-150600.36.10
fixed
suse enterprise desktop 15 SP7
2021.20210325-150600.36.10
fixed
suse enterprise sap 15
2017.20170520-11.8.4
fixed
suse enterprise sap 15 SP1
2017.20170520-11.8.4
fixed
suse enterprise sap 15 SP2
2017.20170520-19.4
fixed
suse enterprise sap 15 SP3
2017.20170520-19.4
fixed
suse enterprise sap 15 SP4
2021.20210325-150400.29.15
fixed
suse enterprise sap 15 SP5
2021.20210325-150400.29.15
fixed
suse enterprise sap 15 SP6
2021.20210325-150600.36.10
fixed
suse enterprise sap 15 SP7
2021.20210325-150600.36.10
fixed
suse enterprise server 15
2017.20170520-11.8.4
fixed
suse enterprise server 15 SP1
2017.20170520-11.8.4
fixed
suse enterprise server 15 SP2
2017.20170520-19.4
fixed
suse enterprise server 15 SP3
2017.20170520-19.4
fixed
suse enterprise server 15 SP4
2021.20210325-150400.29.15
fixed
suse enterprise server 15 SP5
2021.20210325-150400.29.15
fixed
suse enterprise server 15 SP6
2021.20210325-150600.36.10
fixed
suse enterprise server 15 SP7
2021.20210325-150600.36.10
fixed
texlive-bin-devel
suse enterprise desktop 15
2017.20170520-11.8.4
fixed
suse enterprise desktop 15 SP1
2017.20170520-11.8.4
fixed
suse enterprise desktop 15 SP2
2017.20170520-19.4
fixed
suse enterprise desktop 15 SP3
2017.20170520-19.4
fixed
suse enterprise desktop 15 SP4
2021.20210325-150400.29.15
fixed
suse enterprise desktop 15 SP5
2021.20210325-150400.29.15
fixed
suse enterprise desktop 15 SP6
2021.20210325-150600.36.10
fixed
suse enterprise desktop 15 SP7
2021.20210325-150600.36.10
fixed
suse enterprise sap 15
2017.20170520-11.8.4
fixed
suse enterprise sap 15 SP1
2017.20170520-11.8.4
fixed
suse enterprise sap 15 SP2
2017.20170520-19.4
fixed
suse enterprise sap 15 SP3
2017.20170520-19.4
fixed
suse enterprise sap 15 SP4
2021.20210325-150400.29.15
fixed
suse enterprise sap 15 SP5
2021.20210325-150400.29.15
fixed
suse enterprise sap 15 SP6
2021.20210325-150600.36.10
fixed
suse enterprise sap 15 SP7
2021.20210325-150600.36.10
fixed
suse enterprise server 15
2017.20170520-11.8.4
fixed
suse enterprise server 15 SP1
2017.20170520-11.8.4
fixed
suse enterprise server 15 SP2
2017.20170520-19.4
fixed
suse enterprise server 15 SP3
2017.20170520-19.4
fixed
suse enterprise server 15 SP4
2021.20210325-150400.29.15
fixed
suse enterprise server 15 SP5
2021.20210325-150400.29.15
fixed
suse enterprise server 15 SP6
2021.20210325-150600.36.10
fixed
suse enterprise server 15 SP7
2021.20210325-150600.36.10
fixed
texlive-kpathsea-devel
suse enterprise desktop 15
6.2.3-11.8.4
fixed
suse enterprise desktop 15 SP1
6.2.3-11.8.4
fixed
suse enterprise desktop 15 SP2
6.2.3-19.4
fixed
suse enterprise desktop 15 SP3
6.2.3-19.4
fixed
suse enterprise desktop 15 SP4
6.3.3-150400.29.15
fixed
suse enterprise desktop 15 SP5
6.3.3-150400.29.15
fixed
suse enterprise desktop 15 SP6
6.3.3-150600.36.10
fixed
suse enterprise desktop 15 SP7
6.3.3-150600.36.10
fixed
suse enterprise sap 15
6.2.3-11.8.4
fixed
suse enterprise sap 15 SP1
6.2.3-11.8.4
fixed
suse enterprise sap 15 SP2
6.2.3-19.4
fixed
suse enterprise sap 15 SP3
6.2.3-19.4
fixed
suse enterprise sap 15 SP4
6.3.3-150400.29.15
fixed
suse enterprise sap 15 SP5
6.3.3-150400.29.15
fixed
suse enterprise sap 15 SP6
6.3.3-150600.36.10
fixed
suse enterprise sap 15 SP7
6.3.3-150600.36.10
fixed
suse enterprise server 15
6.2.3-11.8.4
fixed
suse enterprise server 15 SP1
6.2.3-11.8.4
fixed
suse enterprise server 15 SP2
6.2.3-19.4
fixed
suse enterprise server 15 SP3
6.2.3-19.4
fixed
suse enterprise server 15 SP4
6.3.3-150400.29.15
fixed
suse enterprise server 15 SP5
6.3.3-150400.29.15
fixed
suse enterprise server 15 SP6
6.3.3-150600.36.10
fixed
suse enterprise server 15 SP7
6.3.3-150600.36.10
fixed
texlive-ptexenc-devel
suse enterprise desktop 15
1.3.5-11.8.4
fixed
suse enterprise desktop 15 SP1
1.3.5-11.8.4
fixed
suse enterprise desktop 15 SP2
1.3.5-19.4
fixed
suse enterprise desktop 15 SP3
1.3.5-19.4
fixed
suse enterprise desktop 15 SP4
1.3.9-150400.29.15
fixed
suse enterprise desktop 15 SP5
1.3.9-150400.29.15
fixed
suse enterprise desktop 15 SP6
1.3.9-150600.36.10
fixed
suse enterprise desktop 15 SP7
1.3.9-150600.36.10
fixed
suse enterprise sap 15
1.3.5-11.8.4
fixed
suse enterprise sap 15 SP1
1.3.5-11.8.4
fixed
suse enterprise sap 15 SP2
1.3.5-19.4
fixed
suse enterprise sap 15 SP3
1.3.5-19.4
fixed
suse enterprise sap 15 SP4
1.3.9-150400.29.15
fixed
suse enterprise sap 15 SP5
1.3.9-150400.29.15
fixed
suse enterprise sap 15 SP6
1.3.9-150600.36.10
fixed
suse enterprise sap 15 SP7
1.3.9-150600.36.10
fixed
suse enterprise server 15
1.3.5-11.8.4
fixed
suse enterprise server 15 SP1
1.3.5-11.8.4
fixed
suse enterprise server 15 SP2
1.3.5-19.4
fixed
suse enterprise server 15 SP3
1.3.5-19.4
fixed
suse enterprise server 15 SP4
1.3.9-150400.29.15
fixed
suse enterprise server 15 SP5
1.3.9-150400.29.15
fixed
suse enterprise server 15 SP6
1.3.9-150600.36.10
fixed
suse enterprise server 15 SP7
1.3.9-150600.36.10
fixed
texlive-synctex-devel
suse enterprise desktop 15
1.18-11.8.4
fixed
suse enterprise desktop 15 SP1
1.18-11.8.4
fixed
suse enterprise desktop 15 SP2
1.18-19.4
fixed
suse enterprise desktop 15 SP3
1.18-19.4
fixed
suse enterprise desktop 15 SP4
1.21-150400.29.15
fixed
suse enterprise desktop 15 SP5
1.21-150400.29.15
fixed
suse enterprise desktop 15 SP6
1.21-150600.36.10
fixed
suse enterprise desktop 15 SP7
1.21-150600.36.10
fixed
suse enterprise sap 15
1.18-11.8.4
fixed
suse enterprise sap 15 SP1
1.18-11.8.4
fixed
suse enterprise sap 15 SP2
1.18-19.4
fixed
suse enterprise sap 15 SP3
1.18-19.4
fixed
suse enterprise sap 15 SP4
1.21-150400.29.15
fixed
suse enterprise sap 15 SP5
1.21-150400.29.15
fixed
suse enterprise sap 15 SP6
1.21-150600.36.10
fixed
suse enterprise sap 15 SP7
1.21-150600.36.10
fixed
suse enterprise server 15
1.18-11.8.4
fixed
suse enterprise server 15 SP1
1.18-11.8.4
fixed
suse enterprise server 15 SP2
1.18-19.4
fixed
suse enterprise server 15 SP3
1.18-19.4
fixed
suse enterprise server 15 SP4
1.21-150400.29.15
fixed
suse enterprise server 15 SP5
1.21-150400.29.15
fixed
suse enterprise server 15 SP6
1.21-150600.36.10
fixed
suse enterprise server 15 SP7
1.21-150600.36.10
fixed
texlive-texlua-devel
suse enterprise desktop 15
5.2.4-11.8.4
fixed
suse enterprise desktop 15 SP1
5.2.4-11.8.4
fixed
suse enterprise desktop 15 SP2
5.2.4-19.4
fixed
suse enterprise desktop 15 SP3
5.2.4-19.4
fixed
suse enterprise desktop 15 SP4
5.3.6-150400.29.15
fixed
suse enterprise desktop 15 SP5
5.3.6-150400.29.15
fixed
suse enterprise desktop 15 SP6
5.3.6-150600.36.10
fixed
suse enterprise desktop 15 SP7
5.3.6-150600.36.10
fixed
suse enterprise sap 15
5.2.4-11.8.4
fixed
suse enterprise sap 15 SP1
5.2.4-11.8.4
fixed
suse enterprise sap 15 SP2
5.2.4-19.4
fixed
suse enterprise sap 15 SP3
5.2.4-19.4
fixed
suse enterprise sap 15 SP4
5.3.6-150400.29.15
fixed
suse enterprise sap 15 SP5
5.3.6-150400.29.15
fixed
suse enterprise sap 15 SP6
5.3.6-150600.36.10
fixed
suse enterprise sap 15 SP7
5.3.6-150600.36.10
fixed
suse enterprise server 15
5.2.4-11.8.4
fixed
suse enterprise server 15 SP1
5.2.4-11.8.4
fixed
suse enterprise server 15 SP2
5.2.4-19.4
fixed
suse enterprise server 15 SP3
5.2.4-19.4
fixed
suse enterprise server 15 SP4
5.3.6-150400.29.15
fixed
suse enterprise server 15 SP5
5.3.6-150400.29.15
fixed
suse enterprise server 15 SP6
5.3.6-150600.36.10
fixed
suse enterprise server 15 SP7
5.3.6-150600.36.10
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
texlive
RHEL 7
2:2012-45.20130427_r30134.el7
fixed
texlive-base
RHEL 7
2:2012-45.20130427_r30134.el7
fixed
texlive-kpathsea-lib
RHEL 7
2:2012-45.20130427_r30134.el7
fixed
texlive-kpathsea-lib-devel
RHEL 7
2:2012-45.20130427_r30134.el7
fixed