VDB

CVE-2011-5244

CVE-2011-5244 PUBLISHED CVSS 6.800000190734863 MEDIUM

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

EPSS 3.36% · 88.2th percentile

Risk Scores

CVSS 2.0
6.800000190734863
EPSS Score
3.36%
88.2th percentile

Affected Products

VendorProductVersions
t1libt1lib
tetextetex3.0
gnomeevince
n/an/an/a

Timeline

  • Nov 19, 2012 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 17, 2022 CVE Updated
  • May 21, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Feb 10, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 27, 2023 EPSS Score
  • Jul 19, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›