Skip to content

[Security] exit(-1) in tex-hyphen HyphenProcessor #69

Description

@eglonnnn

Description

A denial-of-service vulnerability in tex-hyphen CTAN-2024.12.31. When HyphenProcessor processes a crafted hyphenation pattern file, the output offset exceeds the available address space, causing process exit with code -1.

Impact

  • Denial-of-service via unexpected process exit
  • Any application using tex-hyphen to process untrusted pattern files is affected

Reproduction

All materials are available in my research repository:
https://github.com/eglonnnn/opensource-fuzz-vulnerability-research/tree/main/exit(-1)%20in%20tex-hyphen%20HyphenProcessor

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions