CVE-2023-46049 Information
Mar 28, 2024
cve
Description
LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a crafted .o file) to llvm-lto. NOTE: this is disputed because the relationship between pdflatex.fmt and any LLVM language front end is not explained and because a crash of the llvm-lto application should be categorized as a usability problem.
Reference
https://github.com/llvm/llvm-project/issues/67388 http://seclists.org/fulldisclosure/2024/Jan/66 https://llvm.org/docs/Security.html
Share on: