
Cloud Vulnerability DB
A community-led vulnerabilities database
OTFCC v0.10.4 was discovered to contain a heap-buffer overflow vulnerability via /release-x64/otfccdump. The vulnerability affects the texlive-bin package across multiple distributions (Debian Tracker).
The vulnerability is a heap-based buffer overflow that occurs when processing certain input files. When executing the otfccdump command with specific parameters, it can trigger a buffer overflow condition that allows reading beyond allocated memory regions (CVJark Blog).
A successful exploitation of this vulnerability could lead to memory corruption, potentially resulting in program crashes or arbitrary code execution.
The vulnerability can be triggered by providing specially crafted input files to the otfccdump utility. The issue has been confirmed to be exploitable through command line execution with specific parameters (CVJark Blog).
The vulnerability has been fixed in updated versions of the texlive-bin package. Users are advised to update to the patched version. The fix status is marked as 'fixed' in the Debian security tracker (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."