|Category:||Red Hat Local Security Checks|
|Title:||RedHat Security Advisory RHSA-2011:0009|
The remote host is missing updates announced in
Evince is a document viewer.
An array index error was found in the DeVice Independent (DVI) renderer's
PK and VF font file parsers. A DVI file that references a specially-crafted
font file could, when opened, cause Evince to crash or, potentially,
execute arbitrary code with the privileges of the user running Evince.
A heap-based buffer overflow flaw was found in the DVI renderer's AFM font
file parser. A DVI file that references a specially-crafted font file
could, when opened, cause Evince to crash or, potentially, execute
arbitrary code with the privileges of the user running Evince.
An integer overflow flaw was found in the DVI renderer's TFM font file
parser. A DVI file that references a specially-crafted font file could,
when opened, cause Evince to crash or, potentially, execute arbitrary code
with the privileges of the user running Evince. (CVE-2010-2643)
Note: The above issues are not exploitable unless an attacker can trick the
user into installing a malicious font file.
Red Hat would like to thank the Evince development team for reporting these
issues. Upstream acknowledges Jon Larimer of IBM X-Force as the original
reporter of these issues.
Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues.
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date
Risk factor : High
Common Vulnerability Exposure (CVE) ID: CVE-2010-2640|
BugTraq ID: 45678
Debian Security Information: DSA-2357 (Google Search)
SuSE Security Announcement: SUSE-SR:2011:002 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2010-2641
Common Vulnerability Exposure (CVE) ID: CVE-2010-2642
RedHat Security Advisories: RHSA-2012:1201
SuSE Security Announcement: SUSE-SR:2011:005 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2010-2643
|Copyright||Copyright (c) 2011 E-Soft Inc. http://www.securityspace.com|
|This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.