CVE-2011-0433 describes a heap-based buffer overflow in the linetoken function of t1lib, impacting products like teTeX 3.0.x and GNOME evince. This vulnerability can be triggered remotely by a crafted DVI file containing a malicious Adobe Font Metrics (AFM) file. With a CVSS score of 6.8, it carries a medium severity, allowing for potential denial of service and arbitrary code execution with moderate attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:gnome:evince:-:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:t1lib:t1lib:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:tetex:tetex:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.
Nov 2, 2012t1lib: Heap-based buffer overflow DVI file AFM font parser
Jan 30, 2011