Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 444161 - media-libs/t1lib : DoS and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics
Summary: media-libs/t1lib : DoS and possibly execute arbitrary code via a DVI file con...
Status: RESOLVED DUPLICATE of bug 358667
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-11-21 14:12 UTC by Agostino Sarubbo
Modified: 2012-11-21 19:56 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-11-21 14:12:44 UTC
From https://bugzilla.redhat.com/show_bug.cgi?id=878483 :

Common Vulnerabilities and Exposures assigned an identifier CVE-2011-5244 to the following 
vulnerability:

Multiple off-by-one errors in the (1) token and (2) linetoken functions in 
backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other 
products, allow remote attackers to cause a denial of service (crash) and possibly execute 
arbitrary code via a DVI file containing a crafted Adobe Font Metrics ((AFM) file, different 
vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5244
[2] http://www.openwall.com/lists/oss-security/2011/03/04/21
[3] http://git.gnome.org/browse/evince/commit/?id=439c5070022e
[4] http://git.gnome.org/browse/evince/commit/?id=d4139205b010
[5] https://bugzilla.gnome.org/show_bug.cgi?id=643882
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2012-11-21 19:56:38 UTC
Agostino, your script needs to stop creating duplicate bugs.

*** This bug has been marked as a duplicate of bug 358667 ***