Description: | Jon Larimer discovered that Evince�s font parsers incorrectly handled certain buffer lengths when rendering a DVI file. By tricking a user into opening or previewing a DVI file that uses a specially crafted font file, an attacker could crash evince or execute arbitrary code with the user�s privileges. In the default installation of Ubuntu 9.10 and later, attackers would be isolated by the Evince AppArmor profile. |