Lucene search

K
cve[email protected]CVE-2010-0827
HistoryMay 07, 2010 - 6:24 p.m.

CVE-2010-0827

2010-05-0718:24:15
CWE-189
web.nvd.nist.gov
34
cve-2010-0827
integer overflow
dvips
tex live
application crash
arbitrary code
remote attackers
denial of service
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.048 Low

EPSS

Percentile

92.7%

Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted virtual font (VF) file associated with a DVI file.

Affected configurations

NVD
Node
tugtex_liveRange2009
OR
tugtex_liveMatch1996
OR
tugtex_liveMatch1998
OR
tugtex_liveMatch1999
OR
tugtex_liveMatch2000
OR
tugtex_liveMatch2001
OR
tugtex_liveMatch2002
OR
tugtex_liveMatch2003
OR
tugtex_liveMatch2004
OR
tugtex_liveMatch2005
OR
tugtex_liveMatch2007
OR
tugtex_liveMatch2008
Node
tugtetex

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.048 Low

EPSS

Percentile

92.7%