CVE-2010-2643
Publication date 5 January 2011
Last updated 24 July 2024
Ubuntu priority
Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
Status
Package | Ubuntu Release | Status |
---|---|---|
evince | 10.10 maverick |
Fixed 2.32.0-0ubuntu1.1
|
10.04 LTS lucid |
Fixed 2.30.3-0ubuntu1.2
|
|
9.10 karmic |
Fixed 2.28.1-0ubuntu1.3
|
|
8.04 LTS hardy |
Fixed 2.22.2-0ubuntu2.1
|
|
6.06 LTS dapper | Ignored end of life |
References
Related Ubuntu Security Notices (USN)
- USN-1035-1
- Evince vulnerabilities
- 5 January 2011