Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitrary code via a crafted DVI input file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade texlive-bin | Jul 30, 2024 | Nov 13, 2007 |
| Gentoo Linux | — | Upgrade app-text/tetex. | Oct 30, 2017 | Nov 13, 2007 |
| Suse | — | Upgrade te_latexUpgrade texlive-bin-dviljUpgrade texlive-binUpgrade te_kpathUpgrade suse-releaseUpgrade texlive-bin-develUpgrade texlive-bin-cjkUpgrade te_webUpgrade te_dviljUpgrade te_ptexUpgrade tetexUpgrade te_nfsUpgrade te_mpostUpgrade texlive-bin-omegaUpgrade texlive-bin-xetexUpgrade texlive-bin-metapostUpgrade te_amsUpgrade te_eplaiUpgrade texlive-bin-latexUpgrade te_contUpgrade te_omega | Feb 17, 2015 | Nov 13, 2007 |
| Ubuntu | — | Upgrade texlive-extra-utilsUpgrade tetex-bin | Nov 8, 2024 | Nov 13, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub