CVE-2010-0827: Integer Overflow
Dan Rosenberg found a buffer overflow flaw in the way TeX text formatting system processed virtual font files. If a user was tricked into processing a specially-crafted typesetter-independent .dvi (DeVice Independent) file, it could lead to dvips executable crash or, potentially, to arbitrary code execution with the privileges of the user running dvips.
Other sources
Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted virtual font (VF) file associated with a DVI file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0827?
CVE-2010-0827 has a high severity due to the potential for arbitrary code execution from a buffer overflow.
How do I fix CVE-2010-0827?
To fix CVE-2010-0827, update TeX Live or teTeX to the latest version that has addressed this vulnerability.
Which versions of TeX Live are affected by CVE-2010-0827?
CVE-2010-0827 affects TeX Live versions from 1996 to 2009 and certain versions of teTeX.
What is the impact of CVE-2010-0827?
The impact of CVE-2010-0827 includes the possibility of crashes or execution of arbitrary code via specially crafted .dvi files.
Who discovered CVE-2010-0827?
CVE-2010-0827 was discovered by security researcher Dan Rosenberg.