On 23.02.24 16:31, Moritz Mühlenhoff wrote:

Hello Moritz,

The following vulnerability was published for texlive-bin.

CVE-2024-25262[0]:
| texlive-bin commit c515e was discovered to contain heap buffer
| overflow via the function ttfLoadHDMX:ttfdump. This vulnerability
| allows attackers to cause a Denial of Service (DoS) via supplying a
| crafted TTF file.


I'll upload tl-bin -9 soon. Do we need a fix in Debian stable too?

Hilmar
--
Testmail

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to