Are text-only data formats safe? or, use this LATEX class file to Pwn your computer

  • Authors:
  • Stephen Checkoway;Hovav Shacham;Eric Rescorla

  • Affiliations:
  • UC San Diego;UC San Diego;RTFM, Inc.

  • Venue:
  • LEET'10 Proceedings of the 3rd USENIX conference on Large-scale exploits and emergent threats: botnets, spyware, worms, and more
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

We show that malicious TEX, BIBTEX, and METAPOST files can lead to arbitrary code execution, viral infection, denial of service, and data exfiltration, through the file I/O capabilities exposed by TEX's Turing-complete macro language. This calls into doubt the conventional wisdom view that text-only data formats that do not access the network are likely safe. We build a TEX virus that spreads between documents on the MiKTEX distribution onWindows XP; we demonstrate data exfiltration attacks on web-based LATEX previewer services.