VYPR
Unrated severityNVD Advisory· Published May 7, 2010· Updated Apr 29, 2026

CVE-2010-1440

CVE-2010-1440

Description

Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special command in a DVI file, related to the (1) predospecial and (2) bbdospecial functions, a different vulnerability than CVE-2010-0739.

Affected products

13
  • cpe:2.3:a:tug:tetex:*:*:*:*:*:*:*:*
  • Tug/Tex Live12 versions
    cpe:2.3:a:tug:tex_live:*:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:tug:tex_live:*:*:*:*:*:*:*:*range: <=2009
    • cpe:2.3:a:tug:tex_live:1996:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:1998:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:1999:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2000:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2001:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2002:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2003:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2004:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2005:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2007:*:*:*:*:*:*:*
    • cpe:2.3:a:tug:tex_live:2008:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.