CVE-2011-1553
Publication date 31 March 2011
Last updated 24 July 2024
Ubuntu priority
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
Status
Package | Ubuntu Release | Status |
---|---|---|
t1lib | ||
Notes
mdeslaur
xpdf in natty is now built with the poppler engine xpdf in earlier releases seems to use system t1lib
Patch details
Package | Patch details |
---|---|
t1lib |
References
Related Ubuntu Security Notices (USN)
- USN-1335-1
- t1lib vulnerabilities
- 19 January 2012