CVE-2010-0829Improper Restriction of Operations within the Bounds of a Memory Buffer in Dvipng

Severity
4.3MEDIUMNVD
EPSS
5.0%
top 10.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 7
Latest updateMay 2

Description

Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

debiandebian/dvipng< dvipng 1.13-1 (bookworm)
Debianjan-ake_larsson/dvipng< 1.13-1+3
NVDjan-ake_larsson/dvipng1.11, 1.12+1
debiandebian/texlive-bin< dvipng 1.13-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-838g-ff3f-wpf6: Multiple array index errors in set2022-05-02
OSV
CVE-2010-0829: Multiple array index errors in set2010-05-07

📋Vendor Advisories

3
Ubuntu
dvipng vulnerability2010-05-06
Red Hat
dvipng: Multiple array index errors during DVI-to-PNG translation2010-03-25
Debian
CVE-2010-0829: dvipng - Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow r...2010

💬Community

2
Bugzilla
CVE-2010-0829 tetex, dvipng: Multiple array index errors during DVI-to-PNG translation [Fedora all]2010-05-06
Bugzilla
CVE-2010-0829 tetex, dvipng: Multiple array index errors during DVI-to-PNG translation2010-03-16