Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
No PoCs from references.
- https://github.com/tranphuc2005/Privilege-Escalation-Linux-with-JBoss
- https://github.com/tranphuc2005/leoquyen_linux