CVE-2010-2642
t1lib: Heap based buffer overflow in DVI file AFM font parser
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
Desbordamiento de búfer basado en memoria dinámica en el validador de fuentes AFM (AFM font parser) en el componente dvi-backend de Evince v2.32 y anteriores, permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) o puede que ejecutar código de su elección a través de una fuente manipulada junto con un fichero DVI que es procesado por el thumbnailer.
Multiple vulnerabilities have been discovered in T1Lib, the worst of which could lead to remote execution of arbitrary code. Versions less than 5.1.2-r1 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-07-06 CVE Reserved
- 2011-01-07 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-122: Heap-based Buffer Overflow
CAPEC
References (28)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/42872 | Third Party Advisory | |
http://www.securityfocus.com/bid/45678 | Vdb Entry | |
http://www.securitytracker.com/id?1024937 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0056 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0097 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0102 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0193 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0194 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://git.gnome.org/browse/evince/commit/?id=d4139205b010ed06310d14284e63114e88ec6de2 | 2017-07-01 | |
https://bugzilla.redhat.com/show_bug.cgi?id=666318 | 2012-08-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | <= 2.32 Search vendor "Redhat" for product "Evince" and version " <= 2.32" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 0.1 Search vendor "Redhat" for product "Evince" and version "0.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 0.2 Search vendor "Redhat" for product "Evince" and version "0.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 0.3 Search vendor "Redhat" for product "Evince" and version "0.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 0.4 Search vendor "Redhat" for product "Evince" and version "0.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 0.5 Search vendor "Redhat" for product "Evince" and version "0.5" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 0.6 Search vendor "Redhat" for product "Evince" and version "0.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 0.7 Search vendor "Redhat" for product "Evince" and version "0.7" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 0.8 Search vendor "Redhat" for product "Evince" and version "0.8" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 0.9 Search vendor "Redhat" for product "Evince" and version "0.9" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.19 Search vendor "Redhat" for product "Evince" and version "2.19" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.20 Search vendor "Redhat" for product "Evince" and version "2.20" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.21 Search vendor "Redhat" for product "Evince" and version "2.21" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.22 Search vendor "Redhat" for product "Evince" and version "2.22" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.23 Search vendor "Redhat" for product "Evince" and version "2.23" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.24 Search vendor "Redhat" for product "Evince" and version "2.24" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.25 Search vendor "Redhat" for product "Evince" and version "2.25" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.26 Search vendor "Redhat" for product "Evince" and version "2.26" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.27 Search vendor "Redhat" for product "Evince" and version "2.27" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.28 Search vendor "Redhat" for product "Evince" and version "2.28" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.29 Search vendor "Redhat" for product "Evince" and version "2.29" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.29.92 Search vendor "Redhat" for product "Evince" and version "2.29.92" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.30 Search vendor "Redhat" for product "Evince" and version "2.30" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.30.2 Search vendor "Redhat" for product "Evince" and version "2.30.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.30.3 Search vendor "Redhat" for product "Evince" and version "2.30.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.31 Search vendor "Redhat" for product "Evince" and version "2.31" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.31.1 Search vendor "Redhat" for product "Evince" and version "2.31.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.31.2 Search vendor "Redhat" for product "Evince" and version "2.31.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.31.4 Search vendor "Redhat" for product "Evince" and version "2.31.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.31.4.1 Search vendor "Redhat" for product "Evince" and version "2.31.4.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.31.6 Search vendor "Redhat" for product "Evince" and version "2.31.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.31.6.1 Search vendor "Redhat" for product "Evince" and version "2.31.6.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.31.90 Search vendor "Redhat" for product "Evince" and version "2.31.90" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Evince Search vendor "Redhat" for product "Evince" | 2.31.92 Search vendor "Redhat" for product "Evince" and version "2.31.92" | - |
Affected
| ||||||
T1lib Search vendor "T1lib" | T1lib Search vendor "T1lib" for product "T1lib" | 5.1.2 Search vendor "T1lib" for product "T1lib" and version "5.1.2" | - |
Affected
| ||||||
Tug Search vendor "Tug" | Tetex Search vendor "Tug" for product "Tetex" | 3.0 Search vendor "Tug" for product "Tetex" and version "3.0" | - |
Affected
|