PT-2024-5166 · Tex Live+3 · Texlive-Bin+3

·

CVE-2024-25262

·

Published

2024-02-20

·

Updated

2026-04-25

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: texlive-bin version c515e
Description: The issue is related to a heap buffer overflow in the ttfLoadHDMX:ttfdump function of the texlive-bin component in TeX Live computer typesetting systems. This allows attackers to cause a Denial of Service (DoS) by supplying a crafted TTF file. The vulnerability can be exploited by a remote attacker to disrupt service.
Recommendations: For texlive-bin version c515e, consider disabling the ttfLoadHDMX:ttfdump function as a temporary workaround until a patch is available to prevent potential Denial of Service attacks.

Fix

DoS

Buffer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05717
CVE-2024-25262
DLA-3941-1
MGASA-2024-0108
OESA-2026-2110
OESA-2026-2111
OESA-2026-2112
OESA-2026-2113
OESA-2026-2114
USN-6695-1
USN-7985-1

Affected Products

Astra Linux
Linuxmint
Ubuntu
Texlive-Bin