CVE-2010-0739: Buffer Overflow
Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Other sources
Marc Schoenefeld found an integer overflow in the way TeX text formatting system processed special commands. If a user was tricked into processing a specially-crafted typesetter-independent .dvi (DeVice Independent) file, it could lead to dvips executable crash or, potentially, to arbitrary code execution with the privileges of the user running dvips.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2010-0739?
CVE-2010-0739 has a moderate severity rating due to its potential to allow remote code execution through a crafted DVI file.
How do I fix CVE-2010-0739?
To fix CVE-2010-0739, update to the latest stable version of tetex or TeX Live that includes the necessary patches.
What software is affected by CVE-2010-0739?
CVE-2010-0739 affects tetex in Red Hat and TeX Live and teTeX in other distributions.
What type of vulnerability is CVE-2010-0739?
CVE-2010-0739 is an integer overflow vulnerability that may lead to a heap-based buffer overflow.
Can CVE-2010-0739 be exploited without user interaction?
CVE-2010-0739 requires user-assisted exploitation, meaning a user must open a malicious DVI file for the attack to occur.