5
CVSSv2

CVE-2009-1284

Published: 09/04/2009 Updated: 19/04/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in BibTeX 0.99 allows context-dependent malicious users to cause a denial of service (memory corruption and crash) via a long .bib bibliography file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bibtex bibtex 0.99

Vendor Advisories

Debian Bug report logs - #520920 texlive-base-bin: bibtex crashes with large bib file Package: texlive-base-bin; Maintainer for texlive-base-bin is (unknown); Reported by: Vincent Lefevre <vincent@vinc17org> Date: Mon, 23 Mar 2009 16:06:02 UTC Severity: important Tags: patch, security Found in versions texlive-bin/2007d ...
It was discovered that TeX Live incorrectly handled certain long bib bibliography files If a user or automated system were tricked into processing a specially crafted bib file, an attacker could cause a denial of service via application crash This issue only affected Ubuntu 804 LTS, 904 and 910 (CVE-2009-1284) ...

Exploits

Bugtraq ID: 34332 Class: Failure to Handle Exceptional Conditions Published: Apr 01 2009 12:00AM Updated: Nov 13 2009 03:46PM Credit: Vincent Lafevre Vulnerable: RedHat Linux 21 RedHat Fedora 9 0 RedHat Fedora 11 RedHat Fedora 10 RedHat Enterprise Linux WS 5 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 21 ...