← Back to CVE List
Vulnerability Intelligence Report

CVE-2010-2642

Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.

No Active Exploit Signals
CVSS Base Score
7.6
HIGH
EPSS Probability:14.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
redhat evince 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.8, 0.9, 2.19, 2.20, 2.21, 2.22, 2.23, 2.24, 2.25, 2.26, 2.27, 2.28, 2.29, 2.29.92, 2.30, 2.30.2, 2.30.3, 2.31, 2.31.1, 2.31.2, 2.31.4, 2.31.4.1, 2.31.6, 2.31.6.1, 2.31.90, 2.31.92
t1lib t1lib 5.1.2
tug tetex 3.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
14.270%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2010-07-06T00:00:00
Published2011-01-07T18:00:00
Patch Date2011-01-05
Last Updated2024-08-07T02:39:37

LINK COPIED TO CLIPBOARD