{"id":"USN-7985-1","summary":"texlive-bin vulnerabilities","details":"Shin Ando discovered that the Xpdf toolkit embedded in TeX Live incorrectly\nhandled memory when decoding certain data streams. An attacker could\npossibly use this issue to cause TeX Live to crash, resulting in a denial\nof service, or execute arbitrary code. This issue only affected Ubuntu\n20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24106, CVE-2022-24107)\n\nIt was discovered that TeX Live allowed documents to make arbitrary network\nrequests. If a user or automated system were tricked into opening a\nspecially crafted document, a remote attacker could possibly use this issue\nto exfiltrate sensitive information, or perform other network-related\nattacks. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2023-32668)\n\nIt was discovered that TeX Live incorrectly handled certain TrueType fonts.\nIf a user or automated system were tricked into opening a specially crafted\nTrueType font, a remote attacker could use this issue to cause TeX Live to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2024-25262)","modified":"2026-02-10T04:50:48Z","published":"2026-01-29T16:39:12Z","related":["UBUNTU-CVE-2022-24106","UBUNTU-CVE-2022-24107","UBUNTU-CVE-2023-32668","UBUNTU-CVE-2024-25262"],"upstream":["CVE-2022-24106","CVE-2022-24107","CVE-2023-32668","CVE-2024-25262","UBUNTU-CVE-2022-24106","UBUNTU-CVE-2022-24107","UBUNTU-CVE-2023-32668","UBUNTU-CVE-2024-25262"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7985-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-24106"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-24107"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-32668"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-25262"}],"affected":[{"package":{"name":"texlive-bin","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/texlive-bin@2015.20160222.37495-1ubuntu0.1+esm1?arch=source&distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2015.20160222.37495-1ubuntu0.1+esm1"}]}],"versions":["2015.20150524.37493-5build1","2015.20150524.37493-7","2015.20150524.37493-7build1","2015.20150524.37493-7build4","2015.20160222.37495-1","2015.20160222.37495-1ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libkpathsea-dev"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libkpathsea6"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libptexenc-dev"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libptexenc1"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libsynctex-dev"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libsynctex1"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libtexlua52"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libtexlua52-dev"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libtexluajit-dev"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"libtexluajit2"},{"binary_version":"2015.20160222.37495-1ubuntu0.1+esm1","binary_name":"texlive-binaries"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-32668"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2024-25262"}],"ecosystem":"Ubuntu:Pro:16.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7985-1.json"}},{"package":{"name":"texlive-bin","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/texlive-bin@2017.20170613.44572-8ubuntu0.2+esm1?arch=source&distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2017.20170613.44572-8ubuntu0.2+esm1"}]}],"versions":["2017.20170613.44572-5build1","2017.20170613.44572-5build2","2017.20170613.44572-6","2017.20170613.44572-6build1","2017.20170613.44572-6ubuntu1","2017.20170613.44572-8build1","2017.20170613.44572-8ubuntu0.1","2017.20170613.44572-8ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libkpathsea-dev"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libkpathsea6"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libptexenc-dev"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libptexenc1"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libsynctex-dev"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libsynctex1"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libtexlua52"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libtexlua52-dev"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libtexluajit-dev"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"libtexluajit2"},{"binary_version":"2017.20170613.44572-8ubuntu0.2+esm1","binary_name":"texlive-binaries"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-32668"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2024-25262"}],"ecosystem":"Ubuntu:Pro:18.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7985-1.json"}},{"package":{"name":"texlive-bin","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/texlive-bin@2019.20190605.51237-3ubuntu0.2+esm1?arch=source&distro=esm-infra/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2019.20190605.51237-3ubuntu0.2+esm1"}]}],"versions":["2019.20190605.51237-2build1","2019.20190605.51237-3","2019.20190605.51237-3build1","2019.20190605.51237-3build2","2019.20190605.51237-3ubuntu0.1","2019.20190605.51237-3ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libkpathsea-dev"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libkpathsea6"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libptexenc-dev"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libptexenc1"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libsynctex-dev"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libsynctex2"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libtexlua53"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libtexlua53-dev"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libtexluajit-dev"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"libtexluajit2"},{"binary_version":"2019.20190605.51237-3ubuntu0.2+esm1","binary_name":"texlive-binaries"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2022-24106"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2022-24107"}],"ecosystem":"Ubuntu:Pro:20.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7985-1.json"}},{"package":{"name":"texlive-bin","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/texlive-bin@2021.20210626.59705-1ubuntu0.3?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2021.20210626.59705-1ubuntu0.3"}]}],"versions":["2020.20200327.54578-7","2020.20200327.54578-7build1","2021.20210626.59705-1","2021.20210626.59705-1build1","2021.20210626.59705-1ubuntu0.1","2021.20210626.59705-1ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libkpathsea-dev"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libkpathsea6"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libptexenc-dev"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libptexenc1"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libsynctex-dev"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libsynctex2"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libtexlua53"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libtexlua53-dev"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libtexluajit-dev"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"libtexluajit2"},{"binary_version":"2021.20210626.59705-1ubuntu0.3","binary_name":"texlive-binaries"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2022-24106"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2022-24107"}],"ecosystem":"Ubuntu:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7985-1.json"}}],"schema_version":"1.7.3"}