>> GNU Texinfo Texindex "readline()" File Handling Buffer Overflow Vulnerability
Title : GNU Texinfo Texindex "readline()" File Handling Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-4412 CVE ID : CVE-2006-4810
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-11-09
Technical Description
A vulnerability has been identified in GNU Texinfo, which could be exploited by attackers to execute arbitrary commands. This flaw is due to a buffer overflow error in the "readline()" [util/texindex.c] function when handling malformed data, which could be exploited by attackers to crash a vulnerable application or compromise a vulnerable system by tricking a user into processing a specially crafted file using texindex.