PoC Index

CVE-2007-4033

HIGH 7.5EPSS 18.7%

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
18.66% chance of exploitation in the next 30 days, 97th percentile
Published
2007-07-27
Updated
2024-08-07

ExploitDB entries (2)

References

Related