Vulnerability Name: | CVE-2010-0739 (CCN-57886) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2010-04-12 | ||||||||||||||||||||||||||||||||||||
Published: | 2010-04-12 | ||||||||||||||||||||||||||||||||||||
Updated: | 2023-02-13 | ||||||||||||||||||||||||||||||||||||
Summary: | Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow. Note: some of these details are obtained from third party information. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:TF/RC:C)
5.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:TF/RC:C)
5.2 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:TF/RC:C)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-190 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-0739 Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: teTeX GIT Repository texlive-CVE-2010-0739-int-overflow.patch Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: RHSA-2010-0399 Moderate: tetex security update Source: CCN Type: RHSA-2010-0400 Moderate: tetex security update Source: CCN Type: RHSA-2010-0401 Moderate: tetex security update Source: CCN Type: SA39390 Tex Live "predospecial()" Integer Overflow Vulnerability Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: teTeX Web site teTeX Source: CCN Type: OSVDB ID: 63808 Tex Live dospecial.c predospecial() Function DVI File Handling Overflow Source: CCN Type: OSVDB ID: 64388 Tex Live dospecial.c bbdospecial() Function DVI File Handling Overflow Source: CCN Type: BID-39500 TeX Live 'dospecial.c' '.dvi' File Parsing Integer Overflow Vulnerability Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: TeX Live Web site TeX Live Source: CCN Type: USN-937-1 TeX Live vulnerabilities Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: Red Hat Bugzilla Bug 572941 CVE-2010-0739 tetex, texlive: Integer overflow by processing special commands Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: XF Type: UNKNOWN tetex-predospecial-bo(57886) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: SUSE Type: SUSE-SR:2010:013 SUSE Security Summary Report | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1:![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |