CVE-2009-1284

BibTeX 0.99 - Denial of Service via Long .bib File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1284. PoCs published by Vincent Lafevre.

AI-analyzed exploit summary The provided text describes a memory-corruption vulnerability in BibTeX (CVE-2009-1284) due to improper handling of excessively large '.bib' files, potentially leading to denial-of-service or arbitrary code execution. No actual exploit code is included; it is purely an advisory.

Description

Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliography file.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Vincent Lafevre · textdoslinux
https://www.exploit-db.com/exploits/10203

The provided text describes a memory-corruption vulnerability in BibTeX (CVE-2009-1284) due to improper handling of excessively large '.bib' files, potentially leading to denial-of-service or arbitrary code execution. No actual exploit code is included; it is purely an advisory.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Theoretical
Target: BibTeX (various versions, including those shipped with TeTeX or TexLive)
No auth needed
Prerequisites: Ability to deliver a maliciously crafted .bib file to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/04/01/8
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201206-28.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34445
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=492136
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-937-1

Scores

EPSS 0.1598
EPSS Percentile 94.9%

Details

CWE
CWE-119
Status published
Products (1)
bibtex/bibtex 0.99
Published Apr 09, 2009
Tracked Since Feb 18, 2026