CVE-2010-1440: Integer Overflow
An integer overflow was found in the way TeX text formatting system processed special commands. If a user was tricked into processing a specially-crafted typesetter-independent .dvi (DeVice Independent) file, it could lead to dvips executable crash or, potentially, to arbitrary code execution with the privileges of the user running dvips. Different vulnerability than CVE-2010-0739.
Other sources
Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special command in a DVI file, related to the (1) predospecial and (2) bbdospecial functions, a different vulnerability than CVE-2010-0739.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2010-1440?
CVE-2010-1440 has a high severity due to the potential for arbitrary code execution and system crashes.
How do I fix CVE-2010-1440?
To fix CVE-2010-1440, upgrade to the latest version of TeX Live or tetex that addresses this vulnerability.
What are the affected software packages for CVE-2010-1440?
CVE-2010-1440 affects various versions of TeX Live and teTeX including versions from 1996 to 2009.
What could happen if CVE-2010-1440 is exploited?
Exploitation of CVE-2010-1440 could lead to crashes of the dvips executable or arbitrary code execution.
Is CVE-2010-1440 still relevant today?
While CVE-2010-1440 is older, it remains relevant for systems still using vulnerable versions of TeX Live or tetex.