Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Tetex | Tug | * | * |
| Tex_live | Tug | * | * |
| Red Hat Enterprise Linux 3 | RedHat | tetex-0:1.0.7-67.19 | * |
| Red Hat Enterprise Linux 4 | RedHat | tetex-0:2.0.2-22.0.1.EL4.16 | * |
| Red Hat Enterprise Linux 5 | RedHat | tetex-0:3.0-33.8.el5_5.5 | * |
| Texlive-bin | Ubuntu | hardy | * |
| Texlive-bin | Ubuntu | intrepid | * |
| Texlive-bin | Ubuntu | jaunty | * |
| Texlive-bin | Ubuntu | karmic | * |
| Texlive-bin | Ubuntu | lucid | * |
| Texlive-bin | Ubuntu | upstream | * |