CVE-2011-1553
Published: 31 March 2011
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
Notes
Author | Note |
---|---|
mdeslaur | xpdf in natty is now built with the poppler engine xpdf in earlier releases seems to use system t1lib |
Priority
Status
Package | Release | Status |
---|---|---|
t1lib Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Released
(5.1.2-3ubuntu0.10.04.2)
|
|
maverick |
Released
(5.1.2-3ubuntu0.10.10.2)
|
|
natty |
Released
(5.1.2-3ubuntu0.11.04.2)
|
|
oneiric |
Released
(5.1.2-3ubuntu0.11.10.2)
|
|
upstream |
Needs triage
|
|
Patches: vendor: https://bugzilla.redhat.com/show_bug.cgi?id=692909 |