Jump to content

Advisories MDKSA-2007:109: Updated tetex packages fix vulnerabilities


Recommended Posts

Buffer overflow in the gdImageStringFTEx function in gdft.c in the

GD Graphics Library 2.0.33 and earlier allows remote attackers to

cause a denial of service (application crash) and possibly execute

arbitrary code via a crafted string with a JIS encoded font.

 

Tetex 3.x uses an embedded copy of the gd source and may also be

affected by this issue (CVE-2007-0455).

 

A buffer overflow in the open_sty function for makeindex in Tetex

could allow user-assisted remote attackers to overwrite files and

possibly execute arbitrary code via a long filename (CVE-2007-0650).

 

The updated packages have been patched to prevent these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...