CVE-2011-0433

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
gnomeevince
-
t1libt1lib
*
tetextetex
3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
evince
bullseye
3.38.2-1
fixed
bookworm
43.1-2
fixed
sid
46.3.1-1
fixed
trixie
46.3.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
evince
oneiric
not-affected
natty
Fixed 2.32.0-0ubuntu12.4
released
maverick
Fixed 2.32.0-0ubuntu1.2
released
lucid
Fixed 2.30.3-0ubuntu1.3
released
hardy
ignored
t1lib
oneiric
Fixed 5.1.2-3ubuntu0.11.10.2
released
natty
Fixed 5.1.2-3ubuntu0.11.04.2
released
maverick
Fixed 5.1.2-3ubuntu0.10.10.2
released
lucid
Fixed 5.1.2-3ubuntu0.10.04.2
released
karmic
ignored
hardy
ignored
dapper
ignored