Buffer overflow - CVE-2011-1552

 

Buffer overflow - CVE-2011-1552

Published: April 1, 2011 / Updated: August 4, 2020


Vulnerability identifier: #VU33510
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1552
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.


Affected software

aalib (Alpine package)

How to mitigate CVE-2011-1552

Install update from vendor's website.


External References

Related Security Bulletins