Описание
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.
A flaw was found in the SyncTeX parser, part of TeX Live and used by applications like GNOME Evince. A remote attacker could exploit a heap use-after-free vulnerability by providing a specially crafted SyncTeX file (e.g., .synctex or .synctex.gz). This could lead to application crashes or, in severe cases, allow the attacker to execute arbitrary code on the affected system.
Отчет
The SyncTeX parser shipped with TeX Live and embedded by GNOME Evince in Red Hat Enterprise Linux is affected by this vulnerability. A heap use-after-free in synctex_parser.c can be triggered by opening a specially crafted .synctex file, potentially leading to application crashes or code execution. All shipped versions of TeX Live (pre-2026) and evince are within the affected range.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | texlive | Fix deferred | ||
| Red Hat Enterprise Linux 6 | evince | Fix deferred | ||
| Red Hat Enterprise Linux 6 | texlive | Fix deferred | ||
| Red Hat Enterprise Linux 7 | evince | Fix deferred | ||
| Red Hat Enterprise Linux 7 | texlive | Fix deferred | ||
| Red Hat Enterprise Linux 8 | evince | Fix deferred | ||
| Red Hat Enterprise Linux 8 | texlive | Fix deferred | ||
| Red Hat Enterprise Linux 9 | evince | Fix deferred | ||
| Red Hat Enterprise Linux 9 | texlive | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
6.6 Medium
CVSS3
Связанные уязвимости
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedd ...
The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX file can construct a ref node with a NULL parent pointer, causing the replacement routine to fail to detach the node from its sibling chain, which triggers recursive freeing of live tree nodes and leaves dangling pointers that are later accessed by the parser during document load.
6.6 Medium
CVSS3