Vulnerability Description
Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitrary code via a crafted DVI input file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tetex | Tetex | All versions |
| Tug | Texlive 2007 | All versions |
Related Weaknesses (CWE)
References
- http://bugs.gentoo.org/attachment.cgi?id=135423
- http://bugs.gentoo.org/show_bug.cgi?id=198238
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html
- http://secunia.com/advisories/27672Vendor Advisory
- http://secunia.com/advisories/27686Vendor Advisory
- http://secunia.com/advisories/27718Vendor Advisory
- http://secunia.com/advisories/27743Vendor Advisory
- http://secunia.com/advisories/27967Vendor Advisory
- http://secunia.com/advisories/28107Vendor Advisory
- http://secunia.com/advisories/28412Vendor Advisory
- http://secunia.com/advisories/30168Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200711-26.xml
- http://security.gentoo.org/glsa/glsa-200711-34.xml
- http://security.gentoo.org/glsa/glsa-200805-13.xml
FAQ
What is CVE-2007-5937?
CVE-2007-5937 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitrary code via a crafted DVI input file.
How severe is CVE-2007-5937?
CVE-2007-5937 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5937?
Check the references section above for vendor advisories and patch information. Affected products include: Tetex Tetex, Tug Texlive 2007.