Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-0764
HistoryMar 31, 2011 - 12:00 a.m.

CVE-2011-0764

2011-03-3100:00:00
ubuntu.com
ubuntu.com
18

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.278

Percentile

96.8%

t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other
products, uses an invalid pointer in conjunction with a dereference
operation, which allows remote attackers to execute arbitrary code via a
crafted Type 1 font in a PDF document, as demonstrated by
testz.2184122398.pdf.

Notes

Author Note
mdeslaur xpdf in natty is now built with the poppler engine xpdf in earlier releases seems to use system t1lib
jdstrand requested reproducers from report on 2011-10-13
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarcht1lib< 5.1.2-3ubuntu0.10.04.1UNKNOWN
ubuntu10.10noarcht1lib< 5.1.2-3ubuntu0.10.10.1UNKNOWN
ubuntu11.04noarcht1lib< 5.1.2-3ubuntu0.11.04.1UNKNOWN
ubuntu11.10noarcht1lib< 5.1.2-3ubuntu0.11.10.1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.278

Percentile

96.8%