Jump to content

Advisories MDKSA-2007:036: Updated libwmf packages fix embedded gd DoS vulnerability.


paul
 Share

Recommended Posts

Buffer overflow in the gdImageStringFTEx function in gdft.c in the GD

Graphics Library 2.0.33 and earlier allows remote attackers to cause a

denial of service (application crash) and possibly execute arbitrary

code via a crafted string with a JIS encoded font.

 

Libwmf uses an embedded copy of the gd source and may also be affected

by this issue.

 

Packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...