Back

HIGH

t1lib font filename string overflow

Published Jul 27, 2007

Description

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

Affected products

Remediation

Red Hat statement

Not vulnerable. Versions of PHP packages as shipped with current Red Hat products are not linked with t1lib.

Metrics

References (44)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 27, 2007
Updated Aug 7, 2024
Reserved Jul 27, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jul 26, 2007