CVE-2007-5936
Summary
| CVE | CVE-2007-5936 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-11-13 22:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tetex | Tetex | All | All | All | All |
| Application | Tug | Texlive 2007 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| teTeX Buffer Overflows Let Remote Users Execute Arbitrary Code and Unsafe Temporary Files Let Local Users Overwrite Files - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| teTeX Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Advisories:rPSA-2007-0266 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| Fedora update for tetex - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/42238 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Gentoo update for ptex - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| teTeX DVI File Parsing Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Gentoo Linux Documentation -- teTeX: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Support / Security / Advisories / / MDKSA-2007:230 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| SUSE Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo Bug 198238 - app-text/tetex < 3.0_p1-r6 Multiple issues in dviljk and dvips (CVE-2007-{5935,5936,5937}) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Gentoo Linux Documentation -- CSTeX: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [security-announce] SUSE Security Summary Report SUSE-SR:2008:001 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-554-1: teTeX and TeX Live vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| [security-announce] SUSE Security Summary Report SUSE-SR:200?8:011 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| bugs.gentoo.org/attachment.cgi | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| rPath update for tetex - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Gentoo update for tetex - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Bug 368611 – CVE-2007-5936 dviljk uses insecure temporary file | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [SECURITY] Fedora 7 Update: tetex-3.0-40.3.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Mandriva update for tetex - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Ubuntu update for tetex-bin and texlive-bin - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| PTeX: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| issues.rpath.com/browse/RPL-1928 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-05-06 | Mark J Cox | Not vulnerable. teTeX is packaged without the dviljk binary in Red Hat Enterprise Linux, making it impossible to exploit this flaw. We are however including this fix in RHSA-2010:0399, RHSA-2010:0400, and RHSA-2010:0401 in the event the binary is shipped in the future. |
There are currently no legacy QID mappings associated with this CVE.