3.6
CVSSv2

CVE-2007-5936

Published: 13/11/2007 Updated: 15/10/2018
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

dvips in teTeX and TeXlive 2007 and previous versions allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place.

Vulnerable Product Search on Vulmon Subscribe to Product

tetex tetex

tug texlive 2007

Vendor Advisories

Bastien Roucaries discovered that dvips as included in tetex-bin and texlive-bin did not properly perform bounds checking If a user or automated system were tricked into processing a specially crafted dvi file, dvips could be made to crash and execute code as the user invoking the program (CVE-2007-5935) ...