CVE-2007-0455

Impact:
Low
Public Date:
2007-01-26
Bugzilla:
224607: CVE-2007-0455 gd buffer overrun

The MITRE CVE dictionary describes this issue as:

Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.

Find out more about CVE-2007-0455 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=234312

The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (php) RHSA-2007:0153 2007-04-20
Red Hat Enterprise Linux 5 (gd) RHSA-2008:0146 2008-02-28
Red Hat Enterprise Linux 3 (php) RHSA-2007:0155 2007-04-16
Red Hat Application Stack v1 for Enterprise Linux AS (v.4) (php) RHSA-2007:0162 2007-04-16
Red Hat Enterprise Linux 4 (php) RHSA-2007:0155 2007-04-16
Red Hat Enterprise Linux 4 (gd) RHSA-2008:0146 2008-02-28

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 6 libwmf Fix deferred
Red Hat Enterprise Linux 5 libwmf Fix deferred
Red Hat Enterprise Linux 4 libwmf Will not fix

Last Modified

CVE description copyright © 2017, The MITRE Corporation