CVE Vulnerabilities

CVE-2019-18604

Published: Oct 29, 2019 | Modified: May 31, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.

Affected Software

Name Vendor Start Version End Version
Axohelp.c Axohelp.c_project * 1.3 (excluding)
Texlive-bin Ubuntu disco *
Texlive-bin Ubuntu eoan *
Texlive-bin Ubuntu focal *
Texlive-bin Ubuntu trusty *
Texlive-bin Ubuntu upstream *

References