Vulnerability Intelligence Report
CVE-2010-2642
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
No Active Exploit Signals
CVSS Base Score
7.6
HIGH
EPSS Probability:14.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| redhat | evince | 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9, 2.19, 2.20, 2.21, 2.22, 2.23, 2.24, 2.25, 2.26, 2.27, 2.28, 2.29, 2.29.92, 2.30, 2.30.2, 2.30.3, 2.31, 2.31.1, 2.31.2, 2.31.4, 2.31.4.1, 2.31.6, 2.31.6.1, 2.31.90, 2.31.92 |
| t1lib | t1lib | 5.1.2 |
| tug | tetex | 3.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
14.270%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2010-07-06T00:00:00 |
| Published | 2011-01-07T18:00:00 |
| Patch Date | 2011-01-05 |
| Last Updated | 2024-08-07T02:39:37 |
Community Chatter & Buzz