CVE-2010-0829
EPSS 5.0%dvipng - arbitrary code execution
發布日:2010/5/7修改日:2026/4/28
描述
Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.
受影響套件(2)
- Debian/dvipngfrom 0, < 1.13-1
- Debian/dvipngfrom 0, < 1.11-1+lenny1