[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

USN-1035-1 -- evince vulnerabilities

ID: oval:org.secpod.oval:def:700209Date: (C)2011-01-28   (M)2021-09-11
Class: PATCHFamily: unix




Jon Larimer discovered that Evince"s font parsers incorrectly handled certain buffer lengths when rendering a DVI file. By tricking a user into opening or previewing a DVI file that uses a specially crafted font file, an attacker could crash evince or execute arbitrary code with the user"s privileges. In the default installation of Ubuntu 9.10 and later, attackers would be isolated by the Evince AppArmor profile.

Platform:
Ubuntu 8.04
Ubuntu 10.10
Ubuntu 9.10
Ubuntu 10.04
Product:
evince
Reference:
USN-1035-1
CVE-2010-2640
CVE-2010-2641
CVE-2010-2642
CVE-2010-2643
CVE    4
CVE-2010-2642
CVE-2010-2641
CVE-2010-2640
CVE-2010-2643
...
CPE    4
cpe:/o:ubuntu:ubuntu_linux:8.04
cpe:/o:ubuntu:ubuntu_linux:10.04
cpe:/o:ubuntu:ubuntu_linux:9.10
cpe:/o:ubuntu:ubuntu_linux:10.10
...

© SecPod Technologies