5
CVSSv2

CVE-2009-1284

Published: 09/04/2009 Updated: 19/04/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in BibTeX 0.99 allows context-dependent malicious users to cause a denial of service (memory corruption and crash) via a long .bib bibliography file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bibtex bibtex 0.99

Vendor Advisories

It was discovered that TeX Live incorrectly handled certain long bib bibliography files If a user or automated system were tricked into processing a specially crafted bib file, an attacker could cause a denial of service via application crash This issue only affected Ubuntu 804 LTS, 904 and 910 (CVE-2009-1284) ...
Debian Bug report logs - #520920 texlive-base-bin: bibtex crashes with large bib file Package: texlive-base-bin; Maintainer for texlive-base-bin is (unknown); Reported by: Vincent Lefevre <vincent@vinc17org> Date: Mon, 23 Mar 2009 16:06:02 UTC Severity: important Tags: patch, security Found in versions texlive-bin/2007d ...

Exploits

Bugtraq ID: 34332 Class: Failure to Handle Exceptional Conditions Published: Apr 01 2009 12:00AM Updated: Nov 13 2009 03:46PM Credit: Vincent Lafevre Vulnerable: RedHat Linux 21 RedHat Fedora 9 0 RedHat Fedora 11 RedHat Fedora 10 RedHat Enterprise Linux WS 5 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 21 ...