Unrated severityNVD Advisory· Published Jan 7, 2011· Updated Apr 29, 2026
CVE-2010-2642
CVE-2010-2642
Description
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
Affected products
35cpe:2.3:a:redhat:evince:*:*:*:*:*:*:*:*+ 33 more
- cpe:2.3:a:redhat:evince:*:*:*:*:*:*:*:*range: <=2.32
- cpe:2.3:a:redhat:evince:0.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:0.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:0.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:0.4:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:0.9:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.19:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.20:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.21:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.22:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.23:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.24:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.25:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.26:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.27:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.28:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.29:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.29.92:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.30:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.30.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.30.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.31:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.31.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.31.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.31.4:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.31.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.31.6:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.31.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.31.90:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:evince:2.31.92:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
27- git.gnome.org/browse/evince/commit/nvdPatch
- bugzilla.redhat.com/show_bug.cginvdPatch
- secunia.com/advisories/42769nvdVendor Advisory
- secunia.com/advisories/42821nvdVendor Advisory
- secunia.com/advisories/42847nvdVendor Advisory
- www.vupen.com/english/advisories/2011/0029nvdVendor Advisory
- www.vupen.com/english/advisories/2011/0043nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2011-January/052910.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-January/052995.htmlnvd
- lists.mandriva.com/security-announce/2011-01/msg00006.phpnvd
- lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-1201.htmlnvd
- secunia.com/advisories/42872nvd
- www.debian.org/security/2011/dsa-2357nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2011-0009.htmlnvd
- www.securityfocus.com/bid/45678nvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/USN-1035-1nvd
- www.vupen.com/english/advisories/2011/0056nvd
- www.vupen.com/english/advisories/2011/0097nvd
- www.vupen.com/english/advisories/2011/0102nvd
- www.vupen.com/english/advisories/2011/0193nvd
- www.vupen.com/english/advisories/2011/0194nvd
- security.gentoo.org/glsa/201701-57nvd
News mentions
0No linked articles in our index yet.