Jump to content

Advisories MDVSA-2009:231-1: htmldoc


paul
 Share

Recommended Posts

A security vulnerability has been identified and fixed in htmldoc:

 

Buffer overflow in the set_page_size function in util.cxx in HTMLDOC

1.8.27 and earlier allows context-dependent attackers to execute

arbitrary code via a long MEDIA SIZE comment. NOTE: it was later

reported that there were additional vectors in htmllib.cxx and

ps-pdf.cxx using an AFM font file with a long glyph name, but these

vectors do not cross privilege boundaries (CVE-2009-3050).

 

This update provides a solution to this vulnerability.

 

Update:

 

Packages for 2008.0 are being provided due to extended support for

Corporate products.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...