Vulnerability Name: | CVE-2011-5244 (CCN-80271) | ||||||||
Assigned: | 2012-11-19 | ||||||||
Published: | 2012-11-19 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-189 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-5244 Source: MISC Type: UNKNOWN http://git.gnome.org/browse/evince/commit/?id=439c5070022e Source: MISC Type: UNKNOWN http://git.gnome.org/browse/evince/commit/?id=d4139205b010 Source: CCN Type: Evince Web site Evince Simply a document viewer Source: CCN Type: oss-sec mailing list, Fri, 4 Mar 2011 17:13:47 +0100 Re: Re: CVE request: More Evince overflows Source: MLIST Type: UNKNOWN [oss-security] 20110304 Re: Re: CVE request: More Evince overflows Source: CONFIRM Type: UNKNOWN https://bugzilla.gnome.org/show_bug.cgi?id=643882 Source: XF Type: UNKNOWN evince-token-code-exec(80271) Source: XF Type: UNKNOWN evince-token-code-exec(80271) Source: GENTOO Type: UNKNOWN GLSA-201701-57 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |