Vulnerabilities > CVE-2011-5244 - Numeric Errors vulnerability in multiple products
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 | |
Application | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-201701-57.NASL |
description | The remote host is affected by the vulnerability described in GLSA-201701-57 (T1Lib: : Multiple vulnerabilities) Multiple vulnerabilities have been discovered in T1Lib. Please review the CVE identifiers referenced below for details. Impact : Remote attackers, by coercing users to process specially crafted AFM font or PDF file, could cause a Denial of Service condition or execute arbitrary code. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 96710 |
published | 2017-01-24 |
reporter | This script is Copyright (C) 2017 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/96710 |
title | GLSA-201701-57 : T1Lib: : Multiple vulnerabilities |
code |
|
References
- http://git.gnome.org/browse/evince/commit/?id=439c5070022e
- http://git.gnome.org/browse/evince/commit/?id=d4139205b010
- http://www.openwall.com/lists/oss-security/2011/03/04/21
- https://bugzilla.gnome.org/show_bug.cgi?id=643882
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80271
- https://security.gentoo.org/glsa/201701-57