dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place.
CVSS Details
- CVSS 3.1 Base Score: 7.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade texlive-bin | Jul 30, 2024 | Nov 13, 2007 |
| Gentoo Linux | — | Upgrade app-text/tetex. | Oct 30, 2017 | Nov 13, 2007 |
| Suse | — | Upgrade te_omegaUpgrade te_kpathUpgrade te_mpostUpgrade texlive-bin-develUpgrade te_contUpgrade texlive-bin-cjkUpgrade te_ptexUpgrade texlive-bin-dviljUpgrade texlive-binUpgrade tetexUpgrade te_webUpgrade te_nfsUpgrade texlive-bin-latexUpgrade te_latexUpgrade suse-releaseUpgrade texlive-bin-metapostUpgrade texlive-bin-omegaUpgrade te_amsUpgrade te_eplaiUpgrade te_dviljUpgrade texlive-bin-xetex | Feb 17, 2015 | Nov 13, 2007 |
| Ubuntu | — | Upgrade tetex-binUpgrade texlive-extra-utils | Nov 8, 2024 | Nov 13, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub