4.3
CVSSv2

CVE-2010-0829

Published: 07/05/2010 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.

Vulnerable Product Search on Vulmon Subscribe to Product

jan-ake larsson dvipng 1.11

jan-ake larsson dvipng 1.12

tug tetex

Vendor Advisories

Debian Bug report logs - #580628 dvipng: CVE-2010-0829 Package: dvipng; Maintainer for dvipng is Varun Hiremath <varun@debianorg>; Source for dvipng is src:dvipng (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Fri, 7 May 2010 10:09:02 UTC Severity: grave Tags: security Fix ...
Dan Rosenberg discovered that dvipng incorrectly handled certain malformed dvi files If a user or automated system were tricked into processing a specially crafted dvi file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program ...