VYPR
Unrated severityNVD Advisory· Published May 7, 2010· Updated Apr 29, 2026

CVE-2010-0827

CVE-2010-0827

Description

Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted virtual font (VF) file associated with a DVI file.

Affected products

13
  • Tug/Tex Live12 versions
    cpe:2.3:a:tug:tex_live:*:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:tug:tex_live:*:*:*:*:*:*:*:*range: <=2009
    • cpe:2.3:a:tug:tex_live:1996:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:1998:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:1999:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2000:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2001:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2002:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2003:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2004:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2005:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2007:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2008:*:*:*:*:*:*:*
  • cpe:2.3:a:tug:tetex:*:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.