CVE-2010-2642
Summary
| CVE | CVE-2010-2642 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-07 19:00:00 UTC |
| Updated | 2017-07-01 01:29:00 UTC |
| Description | Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 13 Update: evince-2.30.3-2.fc13 |
FEDORA |
lists.fedoraproject.org |
|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| Red Hat update for evince - Advisories - Community |
SECUNIA |
secunia.com |
Vendor Advisory |
| Debian -- Security Information -- DSA-2357-1 evince |
DEBIAN |
www.debian.org |
|
| Evince dvi-backend Multiple Vulnerabilities - Advisories - Community |
SECUNIA |
secunia.com |
Vendor Advisory |
| Bug 666318 – CVE-2010-2642 t1lib: Heap based buffer overflow in DVI file AFM font parser |
CONFIRM |
bugzilla.redhat.com |
Patch |
| Ubuntu update for evince - Advisories - Community |
SECUNIA |
secunia.com |
Vendor Advisory |
| Evince Multiple Remote Code Execution Vulnerabilities |
BID |
www.securityfocus.com |
|
| USN-1035-1: Evince vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Evince Font Parsing Buffer Overflows Let Remote Users Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
|
| evince - View multipage documents |
CONFIRM |
git.gnome.org |
Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
|
| Support / Security / Advisories / / MDVSA-2012:144 | Mandriva |
MANDRIVA |
www.mandriva.com |
|
| [SECURITY] Fedora 14 Update: evince-2.32.0-3.fc14 |
FEDORA |
lists.fedoraproject.org |
|
| Support / Security / Advisories / / MDVSA-2011:016 | Mandriva |
MANDRIVA |
www.mandriva.com |
|
| Support / Security / Advisories / / MDVSA-2011:017 | Mandriva |
MANDRIVA |
www.mandriva.com |
|
| rhn.redhat.com | Red Hat Support |
REDHAT |
www.redhat.com |
|
| Fedora update for evince - Advisories - Community |
SECUNIA |
secunia.com |
|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
|
| mandriva.com |
MANDRIVA |
lists.mandriva.com |
|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:005 |
SUSE |
lists.opensuse.org |
|
| T1Lib: : Multiple vulnerabilities (GLSA 201701-57) — Gentoo Security |
GENTOO |
security.gentoo.org |
|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710532 Gentoo Linux T1Lib Vulnerability (GLSA 201701-57)
- 901524 Common Base Linux Mariner (CBL-Mariner) Security Update for t1lib (7376)