Public Date:
224607: CVE-2007-0455 gd: buffer overrun

The MITRE CVE dictionary describes this issue as:

Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.

Find out more about CVE-2007-0455 from the MITRE CVE dictionary dictionary and NIST NVD.


Red Hat is aware of this issue and is tracking it via the following bug:

The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (php) RHSA-2007:0153 2007-04-20
Red Hat Enterprise Linux 5 (gd) RHSA-2008:0146 2008-02-28
Red Hat Enterprise Linux 3 (php) RHSA-2007:0155 2007-04-16
Red Hat Application Stack v1 for Enterprise Linux AS (v.4) (php) RHSA-2007:0162 2007-04-16
Red Hat Enterprise Linux 4 (php) RHSA-2007:0155 2007-04-16
Red Hat Enterprise Linux 4 (gd) RHSA-2008:0146 2008-02-28

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 6 libwmf Will not fix
Red Hat Enterprise Linux 5 libwmf Will not fix
Red Hat Enterprise Linux 4 libwmf Will not fix
Unless explicitly stated as not affected, all previous versions of packages in any minor update stream of a product listed here should be assumed vulnerable, although may not have been subject to full analysis.
Last Modified

CVE description copyright © 2017, The MITRE Corporation