CVE-2011-0764
published 2011-03-31CVE-2011-0764: t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which…
PriorityP345medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
13.05%
95.9th percentile
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | poppler | < xpdf 3.02-9 (bookworm) | xpdf 3.02-9 (bookworm) |
| debian | xpdf | < xpdf 3.02-9 (bookworm) | xpdf 3.02-9 (bookworm) |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| foolabs | xpdf | — | — |
| glyphandcog | xpdfreader | <= 3.02 | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
| glyphandcog | xpdfreader | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwp8-g83m-q34j: t1lib 5
ghsa_unreviewed·2022-05-14·CVSS 6.8
CVE-2011-1552 [MEDIUM] CWE-119 GHSA-fwp8-g83m-q34j: t1lib 5
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.
GHSA
GHSA-cw28-q96h-5px5: t1lib 5
ghsa_unreviewed·2022-05-14
CVE-2011-0764 [MEDIUM] CWE-20 GHSA-cw28-q96h-5px5: t1lib 5
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.
GHSA
GHSA-23f5-whxg-92j5: Off-by-one error in t1lib 5
ghsa_unreviewed·2022-05-14·CVSS 6.8
CVE-2011-1554 [MEDIUM] GHSA-23f5-whxg-92j5: Off-by-one error in t1lib 5
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.
GHSA
GHSA-6xpf-26gh-gvp9: Use-after-free vulnerability in t1lib 5
ghsa_unreviewed·2022-05-14·CVSS 6.8
CVE-2011-1553 [MEDIUM] GHSA-6xpf-26gh-gvp9: Use-after-free vulnerability in t1lib 5
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
OSV
CVE-2011-0764: t1lib 5
osv·2011-03-31·CVSS 6.8
CVE-2011-0764 [MEDIUM] CVE-2011-0764: t1lib 5
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.
OSV
CVE-2011-1554: Off-by-one error in t1lib 5
osv·2011-03-31·CVSS 6.8
CVE-2011-1554 [MEDIUM] CVE-2011-1554: Off-by-one error in t1lib 5
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.
OSV
CVE-2011-1552: t1lib 5
osv·2011-03-31·CVSS 6.8
CVE-2011-1552 [MEDIUM] CVE-2011-1552: t1lib 5
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.
OSV
CVE-2011-1553: Use-after-free vulnerability in t1lib 5
osv·2011-03-31·CVSS 6.8
CVE-2011-1553 [MEDIUM] CVE-2011-1553: Use-after-free vulnerability in t1lib 5
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
Ubuntu
t1lib vulnerability
vendor_ubuntu·2011-12-21
CVE-2011-0764 t1lib vulnerability
Title: t1lib vulnerability
Summary: t1lib could be made to crash or run programs as your login if it opened a
specially crafted font file.
Jonathan Brossard discovered that t1lib did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause t1lib to crash or possibly execute
arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
t1lib: Off-by-one via crafted Type 1 font
vendor_redhat·2011-03-28·CVSS 6.8
CVE-2011-1554 [MEDIUM] CWE-193 t1lib: Off-by-one via crafted Type 1 font
t1lib: Off-by-one via crafted Type 1 font
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.
Package: tetex (Red Hat Enterprise Linux 4) - Affected
Package: xpdf (Red Hat Enterprise Linux 4) - Not affected
Red Hat
t1lib: Use-after-free via crafted Type 1 font
vendor_redhat·2011-03-28·CVSS 6.8
CVE-2011-1553 [MEDIUM] CWE-416 t1lib: Use-after-free via crafted Type 1 font
t1lib: Use-after-free via crafted Type 1 font
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
Package: tetex (Red Hat Enterprise Linux 4) - Affected
Package: xpdf (Red Hat Enterprise Linux 4) - Not affected
Red Hat
t1lib: invalid read crash via crafted Type 1 font
vendor_redhat·2011-03-28·CVSS 6.8
CVE-2011-1552 [MEDIUM] t1lib: invalid read crash via crafted Type 1 font
t1lib: invalid read crash via crafted Type 1 font
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.
Package: tetex (Red Hat Enterprise Linux 4) - Affected
Package: xpdf (Red Hat Enterprise Linux 4) - Not affected
Red Hat
t1lib: Invalid pointer dereference via crafted Type 1 font
vendor_redhat·2011-03-28·CVSS 6.8
CVE-2011-0764 [MEDIUM] t1lib: Invalid pointer dereference via crafted Type 1 font
t1lib: Invalid pointer dereference via crafted Type 1 font
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.
Package: tetex (Red Hat Enterprise Linux 4) - Affected
Package: xpdf (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2011-1554: poppler - Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teT...
vendor_debian·2011·CVSS 6.8
CVE-2011-1554 [MEDIUM] CVE-2011-1554: poppler - Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teT...
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2011-0764: poppler - t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other produc...
vendor_debian·2011·CVSS 6.8
CVE-2011-0764 [MEDIUM] CVE-2011-0764: poppler - t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other produc...
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2011-1552: poppler - t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other produc...
vendor_debian·2011·CVSS 6.8
CVE-2011-1552 [MEDIUM] CVE-2011-1552: poppler - t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other produc...
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2011-1553: poppler - Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before ...
vendor_debian·2011·CVSS 6.8
CVE-2011-1553 [MEDIUM] CVE-2011-1553: poppler - Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before ...
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2642 CVE-2011-0433 CVE-2011-0764 CVE-2011-1552 CVE-2011-1553 CVE-2011-1554 t1lib various flaws [fedora-all]
bugzilla·2012-01-10·CVSS 7.6
CVE-2010-2642 [HIGH] CVE-2010-2642 CVE-2011-0433 CVE-2011-0764 CVE-2011-1552 CVE-2011-1553 CVE-2011-1554 t1lib various flaws [fedora-all]
CVE-2010-2642 CVE-2011-0433 CVE-2011-0764 CVE-2011-1552 CVE-2011-1553 CVE-2011-1554 t1lib various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedo
Bugzilla
CVE-2011-0764 t1lib: Invalid pointer dereference via crafted Type 1 font
bugzilla·2011-04-01·CVSS 6.8
CVE-2011-0764 [MEDIUM] CVE-2011-0764 t1lib: Invalid pointer dereference via crafted Type 1 font
CVE-2011-0764 t1lib: Invalid pointer dereference via crafted Type 1 font
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0764 to
the following vulnerability:
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6 and other
products, uses an invalid pointer in conjunction with a dereference
operation, which allows remote attackers to execute arbitrary code via
a crafted Type 1 font in a PDF document, as demonstrated by
testz.2184122398.pdf.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0764
[2] http://www.securityfocus.com/archive/1/archive/1/517205/100/0/threaded
[3] http://www.toucan-system.com/advisories/tssa-2011-01.txt
[4] http://www.foolabs.com/xpdf/download.html
[5] http://www.kb.cert.org/vuls/id/MAPG-8ECL8X
[6] http://www.kb.cert.org
Bugzilla
CVE-2011-1554 t1lib: Off-by-one via crafted Type 1 font
bugzilla·2011-04-01·CVSS 6.8
CVE-2011-1554 [MEDIUM] CVE-2011-1554 t1lib: Off-by-one via crafted Type 1 font
CVE-2011-1554 t1lib: Off-by-one via crafted Type 1 font
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1554 to
the following vulnerability:
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before
3.02pl6 and other products, allows remote attackers to cause a denial
of service (application crash) via a PDF document containing a crafted
Type 1 font that triggers an invalid memory read, integer overflow,
and invalid pointer dereference, a different vulnerability than
CVE-2011-0764.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1554
[2] http://www.securityfocus.com/archive/1/archive/1/517205/100/0/threaded
[3] http://www.toucan-system.com/advisories/tssa-2011-01.txt
[4] http://www.foolabs.com/xpdf/download.html
[5] http://www.kb.cer
Bugzilla
CVE-2011-1552 t1lib: invalid read crash via crafted Type 1 font
bugzilla·2011-04-01·CVSS 6.8
CVE-2011-1552 [MEDIUM] CVE-2011-1552 t1lib: invalid read crash via crafted Type 1 font
CVE-2011-1552 t1lib: invalid read crash via crafted Type 1 font
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1552 to
the following vulnerability:
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6 and other
products, reads from invalid memory locations, which allows remote
attackers to cause a denial of service (application crash) via a
crafted Type 1 font in a PDF document, a different vulnerability than
CVE-2011-0764.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1552
[2] http://www.securityfocus.com/archive/1/archive/1/517205/100/0/threaded
[3] http://www.toucan-system.com/advisories/tssa-2011-01.txt
[4] http://www.foolabs.com/xpdf/download.html
[5] http://www.kb.cert.org/vuls/id/MAPG-8ECL8X
[6] http://www.kb.cert.org/vuls/id/3765
Bugzilla
CVE-2011-1553 t1lib: Use-after-free via crafted Type 1 font
bugzilla·2011-04-01·CVSS 6.8
CVE-2011-1553 [MEDIUM] CVE-2011-1553 t1lib: Use-after-free via crafted Type 1 font
CVE-2011-1553 t1lib: Use-after-free via crafted Type 1 font
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1553 to
the following vulnerability:
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in
Xpdf before 3.02pl6 and other products, allows remote attackers to
cause a denial of service (application crash) via a PDF document
containing a crafted Type 1 font that triggers an invalid memory
write, a different vulnerability than CVE-2011-0764.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1553
[2] http://www.securityfocus.com/archive/1/archive/1/517205/100/0/threaded
[3] http://www.toucan-system.com/advisories/tssa-2011-01.txt
[4] http://www.foolabs.com/xpdf/download.html
[5] http://www.kb.cert.org/vuls/id/MAPG-8ECL8X
[6] http
Bugzilla
CVE-2011-0433 CVE-2011-0764 CVE-2011-1552 CVE-2011-1553 CVE-2011-1554 t1lib various flaws [epel-5]
bugzilla·2011-02-23·CVSS 6.8
CVE-2011-0433 [MEDIUM] CVE-2011-0433 CVE-2011-0764 CVE-2011-1552 CVE-2011-1553 CVE-2011-1554 t1lib various flaws [epel-5]
CVE-2011-0433 CVE-2011-0764 CVE-2011-1552 CVE-2011-1553 CVE-2011-1554 t1lib various flaws [epel-5]
epel-5 tracking bug for t1lib: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2011-0764
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=679732,692909
---
Adding parent bug CVE-2011-1552
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=679732,692909,692853
---
Adding parent bug CVE-2011-1553
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=679732,692909,692853,692854
---
Addin
http://rhn.redhat.com/errata/RHSA-2012-1201.htmlhttp://secunia.com/advisories/43823http://secunia.com/advisories/47347http://secunia.com/advisories/48985http://securityreason.com/securityalert/8171http://securitytracker.com/id?1025266http://www.foolabs.com/xpdf/download.htmlhttp://www.kb.cert.org/vuls/id/376500http://www.kb.cert.org/vuls/id/MAPG-8ECL8Xhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:002http://www.mandriva.com/security/advisories?name=MDVSA-2012:144http://www.securityfocus.com/archive/1/517205/100/0/threadedhttp://www.securityfocus.com/bid/46941http://www.toucan-system.com/advisories/tssa-2011-01.txthttp://www.ubuntu.com/usn/USN-1316-1http://www.vupen.com/english/advisories/2011/0728https://exchange.xforce.ibmcloud.com/vulnerabilities/66208https://security.gentoo.org/glsa/201701-57http://rhn.redhat.com/errata/RHSA-2012-1201.htmlhttp://secunia.com/advisories/43823http://secunia.com/advisories/47347http://secunia.com/advisories/48985http://securityreason.com/securityalert/8171http://securitytracker.com/id?1025266http://www.foolabs.com/xpdf/download.htmlhttp://www.kb.cert.org/vuls/id/376500http://www.kb.cert.org/vuls/id/MAPG-8ECL8Xhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:002http://www.mandriva.com/security/advisories?name=MDVSA-2012:144http://www.securityfocus.com/archive/1/517205/100/0/threadedhttp://www.securityfocus.com/bid/46941http://www.toucan-system.com/advisories/tssa-2011-01.txthttp://www.ubuntu.com/usn/USN-1316-1http://www.vupen.com/english/advisories/2011/0728https://exchange.xforce.ibmcloud.com/vulnerabilities/66208https://security.gentoo.org/glsa/201701-57
2011-03-31
Published