CVE
- Id
- 27390
- CVE No.
- CVE-2007-4033
- Status
- Candidate
- Description
- Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.
- Phase
- Assigned (20070727)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 281685 | 27390 | CVE-2007-4033 | BUGTRAQ:20070921 Re: [Full-disclosure] [USN-515-1] t1lib vulnerability | View |
| 281686 | 27390 | CVE-2007-4033 | URL:http://www.securityfocus.com/archive/1/archive/1/480239/100/100/threaded | View |
| 281687 | 27390 | CVE-2007-4033 | BUGTRAQ:20070921 Re: [USN-515-1] t1lib vulnerability | View |
| 281688 | 27390 | CVE-2007-4033 | URL:http://www.securityfocus.com/archive/1/archive/1/480244/100/100/threaded | View |
| 281689 | 27390 | CVE-2007-4033 | BUGTRAQ:20080105 rPSA-2008-0007-1 tetex tetex-afm tetex-dvips tetex-fonts tetex-latex tetex-xdvi | View |
| 281690 | 27390 | CVE-2007-4033 | URL:http://www.securityfocus.com/archive/1/archive/1/485823/100/0/threaded | View |
| 281691 | 27390 | CVE-2007-4033 | BUGTRAQ:20080212 FLEA-2008-0006-1 tetex tetex-dvips tetex-fonts | View |
| 281692 | 27390 | CVE-2007-4033 | URL:http://www.securityfocus.com/archive/1/archive/1/487984/100/0/threaded | View |
| 281693 | 27390 | CVE-2007-4033 | MISC:http://www.bugtraq.ir/adv/t1lib.txt | View |
| 281694 | 27390 | CVE-2007-4033 | MILW0RM:4227 | View |
| 281695 | 27390 | CVE-2007-4033 | URL:http://www.milw0rm.com/exploits/4227 | View |
| 281696 | 27390 | CVE-2007-4033 | MISC:https://bugzilla.redhat.com/show_bug.cgi?id=303021 | View |
| 281697 | 27390 | CVE-2007-4033 | CONFIRM:http://bugs.gentoo.org/show_bug.cgi?id=193437 | View |
| 281698 | 27390 | CVE-2007-4033 | CONFIRM:https://issues.rpath.com/browse/RPL-1972 | View |
| 281699 | 27390 | CVE-2007-4033 | CONFIRM:http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0007 | View |
| 281700 | 27390 | CVE-2007-4033 | DEBIAN:DSA-1390 | View |
| 281701 | 27390 | CVE-2007-4033 | URL:http://www.debian.org/security/2007/dsa-1390 | View |
| 281702 | 27390 | CVE-2007-4033 | FEDORA:FEDORA-2007-2343 | View |
| 281703 | 27390 | CVE-2007-4033 | URL:http://fedoranews.org/updates/FEDORA-2007-234.shtml | View |
| 281704 | 27390 | CVE-2007-4033 | FEDORA:FEDORA-2007-3390 | View |
| 281705 | 27390 | CVE-2007-4033 | URL:https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.html | View |
| 281706 | 27390 | CVE-2007-4033 | FEDORA:FEDORA-2007-750 | View |
| 281707 | 27390 | CVE-2007-4033 | URL:https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00724.html | View |
| 281708 | 27390 | CVE-2007-4033 | GENTOO:GLSA-200710-12 | View |
| 281709 | 27390 | CVE-2007-4033 | URL:http://security.gentoo.org/glsa/glsa-200710-12.xml | View |
| 281710 | 27390 | CVE-2007-4033 | GENTOO:GLSA-200711-34 | View |
| 281711 | 27390 | CVE-2007-4033 | URL:http://security.gentoo.org/glsa/glsa-200711-34.xml | View |
| 281712 | 27390 | CVE-2007-4033 | GENTOO:GLSA-200805-13 | View |
| 281713 | 27390 | CVE-2007-4033 | URL:http://security.gentoo.org/glsa/glsa-200805-13.xml | View |
| 281714 | 27390 | CVE-2007-4033 | MANDRIVA:MDKSA-2007:189 | View |
| 281715 | 27390 | CVE-2007-4033 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:189 | View |
| 281716 | 27390 | CVE-2007-4033 | MANDRIVA:MDKSA-2007:230 | View |
| 281717 | 27390 | CVE-2007-4033 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:230 | View |
| 281718 | 27390 | CVE-2007-4033 | REDHAT:RHSA-2007:1027 | View |
| 281719 | 27390 | CVE-2007-4033 | URL:http://www.redhat.com/support/errata/RHSA-2007-1027.html | View |
| 281720 | 27390 | CVE-2007-4033 | REDHAT:RHSA-2007:1030 | View |
| 281721 | 27390 | CVE-2007-4033 | URL:http://www.redhat.com/support/errata/RHSA-2007-1030.html | View |
| 281722 | 27390 | CVE-2007-4033 | REDHAT:RHSA-2007:1031 | View |
| 281723 | 27390 | CVE-2007-4033 | URL:http://www.redhat.com/support/errata/RHSA-2007-1031.html | View |
| 281724 | 27390 | CVE-2007-4033 | SUSE:SUSE-SR:2007:023 | View |
| 281725 | 27390 | CVE-2007-4033 | URL:http://www.novell.com/linux/security/advisories/2007_23_sr.html | View |
| 281726 | 27390 | CVE-2007-4033 | UBUNTU:USN-515-1 | View |
| 281727 | 27390 | CVE-2007-4033 | URL:http://www.ubuntu.com/usn/usn-515-1 | View |
| 281728 | 27390 | CVE-2007-4033 | BID:25079 | View |
| 281729 | 27390 | CVE-2007-4033 | URL:http://www.securityfocus.com/bid/25079 | View |
| 281730 | 27390 | CVE-2007-4033 | OVAL:oval:org.mitre.oval:def:10557 | View |
| 281731 | 27390 | CVE-2007-4033 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10557 | View |
| 281732 | 27390 | CVE-2007-4033 | SECTRACK:1018905 | View |
| 281733 | 27390 | CVE-2007-4033 | URL:http://www.securitytracker.com/id?1018905 | View |
| 281734 | 27390 | CVE-2007-4033 | SECUNIA:26241 | View |
| 281735 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/26241 | View |
| 281736 | 27390 | CVE-2007-4033 | SECUNIA:26992 | View |
| 281737 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/26992 | View |
| 281738 | 27390 | CVE-2007-4033 | SECUNIA:26981 | View |
| 281739 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/26981 | View |
| 281740 | 27390 | CVE-2007-4033 | SECUNIA:26901 | View |
| 281741 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/26901 | View |
| 281742 | 27390 | CVE-2007-4033 | SECUNIA:27239 | View |
| 281743 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/27239 | View |
| 281744 | 27390 | CVE-2007-4033 | SECUNIA:27599 | View |
| 281745 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/27599 | View |
| 281746 | 27390 | CVE-2007-4033 | SECUNIA:27297 | View |
| 281747 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/27297 | View |
| 281748 | 27390 | CVE-2007-4033 | SECUNIA:27743 | View |
| 281749 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/27743 | View |
| 281750 | 27390 | CVE-2007-4033 | SECUNIA:27439 | View |
| 281751 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/27439 | View |
| 281752 | 27390 | CVE-2007-4033 | SECUNIA:28345 | View |
| 281753 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/28345 | View |
| 281754 | 27390 | CVE-2007-4033 | SECUNIA:27718 | View |
| 281755 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/27718 | View |
| 281756 | 27390 | CVE-2007-4033 | SECUNIA:30168 | View |
| 281757 | 27390 | CVE-2007-4033 | URL:http://secunia.com/advisories/30168 | View |
| 281758 | 27390 | CVE-2007-4033 | XF:php-imagepsloadfont-bo(35620) | View |