CVE-2010-0829: Buffer Overflow
Dan Rosenberg reported multiple instances of an array index error in the way TeX text formatting system translated typesetter-independent .dvi (DeVice Independent) files into their Portable Network Graphics (PNG) alternatives. If a user was tricked into translation of a specially-crafted DVI file(s) into its PNG equivalent(s), it could lead to dvipng executable crash.
Other sources
Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0829?
CVE-2010-0829 has a medium severity level due to the potential for arbitrary code execution.
How do I fix CVE-2010-0829?
To fix CVE-2010-0829, you should upgrade to versions 1.11 or 1.12 of dvipng or use an alternative TeX distribution.
What software is affected by CVE-2010-0829?
CVE-2010-0829 affects dvipng versions 1.11 and 1.12, as well as the teTeX distribution.
What attack vectors are associated with CVE-2010-0829?
CVE-2010-0829 may be exploited if a user is tricked into processing a specially-crafted DVI file.
Who reported CVE-2010-0829?
CVE-2010-0829 was reported by security researcher Dan Rosenberg.