6.8
CVSSv2

CVE-2010-0739

Published: 16/04/2010 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote malicious users to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

tug tetex

tug tex live

Vendor Advisories

It was discovered that TeX Live incorrectly handled certain long bib bibliography files If a user or automated system were tricked into processing a specially crafted bib file, an attacker could cause a denial of service via application crash This issue only affected Ubuntu 804 LTS, 904 and 910 (CVE-2009-1284) ...
Debian Bug report logs - #580668 texlive-bin: Fix arbitrary code execution via integer overflow Package: texlive-bin; Maintainer for texlive-bin is Debian TeX Maintainers <debian-tex-maint@listsdebianorg>; Reported by: أحمد المحمودي <aelmahmoudy@sabilyorg> Date: Fri, 7 May 2010 16:03:01 UTC Severity: ...