CVE-2011-0764: Input Validation
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0764?
CVE-2011-0764 has a high severity rating due to its potential for remote code execution via crafted PDF documents.
How do I fix CVE-2011-0764?
To fix CVE-2011-0764, users should upgrade to a patched version of t1lib or any affected software that addresses this vulnerability.
Which versions of t1lib are affected by CVE-2011-0764?
CVE-2011-0764 affects t1lib versions 5.1.2 and earlier.
Can CVE-2011-0764 be exploited remotely?
Yes, CVE-2011-0764 can be exploited remotely by attacking systems that process specifically crafted PDF files with vulnerable t1lib versions.
What are the potential consequences of CVE-2011-0764?
The consequences of CVE-2011-0764 include unauthorized arbitrary code execution, which could lead to system compromise.