6.8
CVSSv2

CVE-2007-5935

Published: 13/11/2007 Updated: 15/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and previous versions allows user-assisted malicious users to execute arbitrary code via a DVI file with a long href tag.

Vulnerable Product Search on Vulmon Subscribe to Product

tetex tetex

tug texlive 2007

Vendor Advisories

Bastien Roucaries discovered that dvips as included in tetex-bin and texlive-bin did not properly perform bounds checking If a user or automated system were tricked into processing a specially crafted dvi file, dvips could be made to crash and execute code as the user invoking the program (CVE-2007-5935) ...