Lucene search

K
cve[email protected]CVE-2010-1440
HistoryMay 07, 2010 - 6:24 p.m.

CVE-2010-1440

2010-05-0718:24:15
CWE-189
web.nvd.nist.gov
35
cve-2010-1440
integer overflow
dvips
tex live
denial of service
remote attackers
arbitrary code
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.145 Low

EPSS

Percentile

95.8%

Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special command in a DVI file, related to the (1) predospecial and (2) bbdospecial functions, a different vulnerability than CVE-2010-0739.

Affected configurations

NVD
Node
tugtetex
OR
tugtex_liveRange≀2009
OR
tugtex_liveMatch1996
OR
tugtex_liveMatch1998
OR
tugtex_liveMatch1999
OR
tugtex_liveMatch2000
OR
tugtex_liveMatch2001
OR
tugtex_liveMatch2002
OR
tugtex_liveMatch2003
OR
tugtex_liveMatch2004
OR
tugtex_liveMatch2005
OR
tugtex_liveMatch2007
OR
tugtex_liveMatch2008

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.145 Low

EPSS

Percentile

95.8%