Lucene search

K
cve[email protected]CVE-2011-0764
HistoryMar 31, 2011 - 10:55 p.m.

CVE-2011-0764

2011-03-3122:55:02
CWE-20
web.nvd.nist.gov
40
cve-2011-0764
t1lib
xpdf
tetex
remote code execution
type 1 font
pdf document
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.278 Low

EPSS

Percentile

96.8%

t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.

Affected configurations

NVD
Node
t1libt1libRange5.1.2
OR
t1libt1libMatch0.1alpha
OR
t1libt1libMatch0.2beta
OR
t1libt1libMatch0.3beta
OR
t1libt1libMatch0.4beta
OR
t1libt1libMatch0.5beta
OR
t1libt1libMatch0.6beta
OR
t1libt1libMatch0.7beta
OR
t1libt1libMatch0.8beta
OR
t1libt1libMatch0.9
OR
t1libt1libMatch0.9.1
OR
t1libt1libMatch0.9.2
OR
t1libt1libMatch1.0
OR
t1libt1libMatch1.0.1
OR
t1libt1libMatch1.1.0
OR
t1libt1libMatch1.1.1
OR
t1libt1libMatch1.2
OR
t1libt1libMatch1.3
OR
t1libt1libMatch1.3.1
OR
t1libt1libMatch5.0.0
OR
t1libt1libMatch5.0.1
OR
t1libt1libMatch5.0.2
OR
t1libt1libMatch5.1.0
OR
t1libt1libMatch5.1.1
AND
foolabsxpdfMatch0.5a
OR
foolabsxpdfMatch0.7a
OR
foolabsxpdfMatch0.91a
OR
foolabsxpdfMatch0.91b
OR
foolabsxpdfMatch0.91c
OR
foolabsxpdfMatch0.92a
OR
foolabsxpdfMatch0.92b
OR
foolabsxpdfMatch0.92c
OR
foolabsxpdfMatch0.92d
OR
foolabsxpdfMatch0.92e
OR
foolabsxpdfMatch0.93a
OR
foolabsxpdfMatch0.93b
OR
foolabsxpdfMatch0.93c
OR
foolabsxpdfMatch1.00a
OR
foolabsxpdfMatch3.0.1
OR
foolabsxpdfMatch3.02pl1
OR
foolabsxpdfMatch3.02pl2
OR
foolabsxpdfMatch3.02pl3
OR
foolabsxpdfMatch3.02pl4
OR
glyphandcogxpdfreaderRange3.02
OR
glyphandcogxpdfreaderMatch0.2
OR
glyphandcogxpdfreaderMatch0.3
OR
glyphandcogxpdfreaderMatch0.4
OR
glyphandcogxpdfreaderMatch0.5
OR
glyphandcogxpdfreaderMatch0.6
OR
glyphandcogxpdfreaderMatch0.7
OR
glyphandcogxpdfreaderMatch0.80
OR
glyphandcogxpdfreaderMatch0.90
OR
glyphandcogxpdfreaderMatch0.91
OR
glyphandcogxpdfreaderMatch0.92
OR
glyphandcogxpdfreaderMatch0.93
OR
glyphandcogxpdfreaderMatch1.00
OR
glyphandcogxpdfreaderMatch1.01
OR
glyphandcogxpdfreaderMatch2.00
OR
glyphandcogxpdfreaderMatch2.01
OR
glyphandcogxpdfreaderMatch2.02
OR
glyphandcogxpdfreaderMatch2.03
OR
glyphandcogxpdfreaderMatch3.00
OR
glyphandcogxpdfreaderMatch3.01
OR
glyphandcogxpdfreaderMatch3.02

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.278 Low

EPSS

Percentile

96.8%