CVE-2011-0433

EUVD-2011-0458
Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
gnomeevince
-
t1libt1lib
*
tetextetex
3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
evince
bookworm
43.1-2
fixed
bullseye
3.38.2-1
fixed
sid
46.3.1-1
fixed
trixie
46.3.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
evince
hardy
ignored
lucid
Fixed 2.30.3-0ubuntu1.3
released
maverick
Fixed 2.32.0-0ubuntu1.2
released
natty
Fixed 2.32.0-0ubuntu12.4
released
oneiric
not-affected
t1lib
dapper
ignored
hardy
ignored
karmic
ignored
lucid
Fixed 5.1.2-3ubuntu0.10.04.2
released
maverick
Fixed 5.1.2-3ubuntu0.10.10.2
released
natty
Fixed 5.1.2-3ubuntu0.11.04.2
released
oneiric
Fixed 5.1.2-3ubuntu0.11.10.2
released