CVE-2004-2167

latex2rtf 1.9.15 - Buffer Overflow via expandmacro Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-2167. PoCs published by D. J. Bernstein, uzzzval.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in LaTeX2rtf version 1.9.15 by crafting a malicious LaTeX file. It includes shellcode to create a file named 'EXPLOITED' and uses a stack-based overflow to execute arbitrary code.

Description

Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro function, and possibly (2) Environments and (3) TranslateCommand.

Exploits (2)

exploitdb WORKING POC VERIFIED
by D. J. Bernstein · cremotelinux
https://www.exploit-db.com/exploits/24622

This exploit targets a buffer overflow vulnerability in LaTeX2rtf version 1.9.15 by crafting a malicious LaTeX file. It includes shellcode to create a file named 'EXPLOITED' and uses a stack-based overflow to execute arbitrary code.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: LaTeX2rtf 1.9.15
No auth needed
Prerequisites: Victim must process the malicious LaTeX file with LaTeX2rtf
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by uzzzval · poc
https://github.com/uzzzval/cve-2004-2167

This repository contains a functional exploit for CVE-2004-2167, a buffer overflow vulnerability in LaTeX2RTF. The exploit generates a malicious .tex file that triggers the vulnerability when processed by LaTeX2RTF, leading to arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: LaTeX2RTF version 1.9.15
No auth needed
Prerequisites: LaTeX2RTF installed on the target system · Ability to deliver a malicious .tex file to the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_sectrack
http://www.securitytracker.com/alerts/2004/Sep/1011367.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17487
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11233
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/displayvuln.php?osvdb_id=10216
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17460

Scores

EPSS 0.1431
EPSS Percentile 96.1%

Details

Status published
Products (1)
latex2rtf/latex2rtf 1.9.15
Published Dec 31, 2004
Tracked Since Feb 18, 2026