Description
A denial-of-service vulnerability in tex-hyphen CTAN-2024.12.31. When HyphenProcessor processes a crafted hyphenation pattern file, the output offset exceeds the available address space, causing process exit with code -1.
Impact
- Denial-of-service via unexpected process exit
- Any application using tex-hyphen to process untrusted pattern files is affected
Reproduction
All materials are available in my research repository:
https://github.com/eglonnnn/opensource-fuzz-vulnerability-research/tree/main/exit(-1)%20in%20tex-hyphen%20HyphenProcessor
Description
A denial-of-service vulnerability in tex-hyphen CTAN-2024.12.31. When
HyphenProcessorprocesses a crafted hyphenation pattern file, the output offset exceeds the available address space, causing process exit with code -1.Impact
Reproduction
All materials are available in my research repository:
https://github.com/eglonnnn/opensource-fuzz-vulnerability-research/tree/main/exit(-1)%20in%20tex-hyphen%20HyphenProcessor