ubuntu · CVE-2007-4033

Quick triage

Priority: medium Published: 2007-07-27 22:30:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2007-4033 medium priority: Ubuntu including 3 source packages (t1lib, tetex-bin, texlive-bin), 14 status rows across 5 suites (dapper, edgy, feisty, gutsy, upstream): not-affected 6, needs-triage 3, released 3, DNE 2.

Description:

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

cvelogic Threat Intelligence