First published: Tue Mar 16 2010(Updated: )
Dan Rosenberg reported multiple instances of an array index error in the way TeX text formatting system translated typesetter-independent .dvi (DeVice Independent) files into their Portable Network Graphics (PNG) alternatives. If a user was tricked into translation of a specially-crafted DVI file(s) into its PNG equivalent(s), it could lead to dvipng executable crash.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
dvipng | =1.11 | |
dvipng | =1.12 | |
teTeX |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0829 has a medium severity level due to the potential for arbitrary code execution.
To fix CVE-2010-0829, you should upgrade to versions 1.11 or 1.12 of dvipng or use an alternative TeX distribution.
CVE-2010-0829 affects dvipng versions 1.11 and 1.12, as well as the teTeX distribution.
CVE-2010-0829 may be exploited if a user is tricked into processing a specially-crafted DVI file.
CVE-2010-0829 was reported by security researcher Dan Rosenberg.