Path to this page:
Subject: CVS commit: pkgsrc/print/dvipsk
From: Min Sik Kim
Date: 2010-06-08 17:17:05
Message id: 20100608151705.39CE2175DD@cvs.netbsd.org
Log Message:
Fix CVE-2010-1440. Patch from TeX Live repository.
Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX
Live 2009 and earlier, and teTeX, allow remote attackers to cause a
denial of service (application crash) or possibly execute arbitrary
code via a special command in a DVI file, related to the (1)
predospecial and (2) bbdospecial functions, a different
vulnerability than CVE-2010-0739.
Files: