VDB
BDU%3A2024-05717
BDU%3A2024-05717
PUBLISHED
CVSS 10 CRITICAL
Уязвимость функции ttfLoadHDMX:ttfdump компонента texlive-bin систем компьютерной верстки TeX Live, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| tug | tex_live | c515e |
| Canonical Ltd., ООО «РусБИТех-Астра», TeX Users Group | Ubuntu, Astra Linux Special Edition (запись в едином реестре российских программ №369), Astra Linux Common Edition (запись в едином реестре российских программ №4433), texlive-bin | |
| n/a | n/a | n/a |
Timeline
- Feb 20, 2024 CVE Published
- Jan 20, 2026 CVE Updated
- Mar 19, 2026 Distribution Patch
References
- https://security.snyk.io/vuln/SNYK-DEBIAN12-TEXLIVEBIN-6261580 url
- https://ubuntu.com/security/notices/USN-6695-1 url
- https://packetstormsecurity.com/files/cve/CVE-2024-25262 url
- https://github.com/TeX-Live/texlive-source/pull/63 advisory
- https://bugs.launchpad.net/ubuntu/+source/texlive-bin/+bug/2047912 url
- https://lists.debian.org/debian-lts-announce/2024/10/msg00032.html url
- https://tug.org/svn/texlive/trunk/Build/source/texk/ttfdump/ChangeLog?revision=69605&view=co url
- https://vuldb.com/?id.254215 url
- https://www.tenable.com/plugins/nessus/192119 url
- https://github.com/NixOS/nixpkgs/pull/298721/commits/3b9901da0ed48468db1887237f0e6e267119bf3c url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0319SE17 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20251225SE16 url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0114SE18MD advisory
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-0422SE47 advisory