MEDIUM · 6.8

CVE-2011-0764

t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitr...

Vulnerability Description

t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
T1LibT1Lib<= 5.1.2
FoolabsXpdf0.5a
GlyphandcogXpdfreader<= 3.02

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-0764?

CVE-2011-0764 is a vulnerability with a CVSS score of 6.8 (MEDIUM). t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitr...

How severe is CVE-2011-0764?

CVE-2011-0764 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-0764?

Check the references section above for vendor advisories and patch information. Affected products include: T1Lib T1Lib, Foolabs Xpdf, Glyphandcog Xpdfreader.