Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2011-0433

Published: 13 January 2012

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.

Notes

AuthorNote
mdeslaur
original patch had an off by one, see second gnome bug
patch for t1lib in RH bug
jdstrand
5.1.2-3.4 in Debian claims to have fixed this, but the patch wasn't
applied

Priority

Medium

Status

Package Release Status
evince
Launchpad, Ubuntu, Debian
hardy Ignored
(end of life)
lucid
Released (2.30.3-0ubuntu1.3)
maverick
Released (2.32.0-0ubuntu1.2)
natty
Released (2.32.0-0ubuntu12.4)
oneiric Not vulnerable
(3.2.1-0ubuntu2)
upstream Needs triage

Patches:
upstream: http://git.gnome.org/browse/evince/patch/?id=439c5070022eab6cef7266aab47f978058012c72
upstream: http://git.gnome.org/browse/evince/patch/?id=efadec4ffcdde3373f6f4ca0eaac98dc963c4fd5
This vulnerability is mitigated in part by an AppArmor profile.
t1lib
Launchpad, Ubuntu, Debian
dapper Ignored
(end of life)
hardy Ignored
(end of life)
karmic Ignored
(end of life)
lucid
Released (5.1.2-3ubuntu0.10.04.2)
maverick
Released (5.1.2-3ubuntu0.10.10.2)
natty
Released (5.1.2-3ubuntu0.11.04.2)
oneiric
Released (5.1.2-3ubuntu0.11.10.2)
upstream Pending
(5.1.2-3.5)