CVE-2007-4033

Impact:
Moderate
Public Date:
2007-07-26
Bugzilla:
352271: CVE-2007-4033 t1lib font filename string overflow

The MITRE CVE dictionary describes this issue as:

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

Find out more about CVE-2007-4033 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Not vulnerable. Versions of PHP packages as shipped with current Red Hat products are not linked with t1lib.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 3 (xpdf) RHSA-2007:1030 2007-11-07
Red Hat Enterprise Linux 2.1 (xpdf) RHSA-2007:1031 2007-11-07
Red Hat Enterprise Linux 5 (tetex) RHSA-2007:1027 2007-11-08
Red Hat Enterprise Linux 4 (tetex) RHSA-2007:1027 2007-11-08
Last Modified

CVE description copyright © 2017, The MITRE Corporation