LOW · 3.6

CVE-2007-5936

dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which ca...

Vulnerability Description

dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place.

CVSS Score

3.6

LOW

AV:L/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
TetexTetexAll versions
TugTexlive 2007All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5936?

CVE-2007-5936 is a vulnerability with a CVSS score of 3.6 (LOW). dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which ca...

How severe is CVE-2007-5936?

CVE-2007-5936 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5936?

Check the references section above for vendor advisories and patch information. Affected products include: Tetex Tetex, Tug Texlive 2007.