VDB
CVE-2007-4033
CVE-2007-4033
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.
EPSS 18.66% · 97.1th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
18.66%
97.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| t1lib | t1lib | 5.1.1 |
| php | php | 5.2.3 |
Timeline
- Jul 27, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
- Feb 14, 2024 EPSS Score
References
- GLSA-200710-12 vendor-advisory
- 27743 third-party-advisory
- 26901 third-party-advisory
- 20070921 Re: [Full-disclosure] [USN-515-1] t1lib vulnerability mailing-list
- DSA-1390 vendor-advisory
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0007 url
- RHSA-2007:1031 vendor-advisory
- 27239 third-party-advisory
- 26241 third-party-advisory
- 20070921 Re: [USN-515-1] t1lib vulnerability mailing-list
- 25079 vdb
- 27718 third-party-advisory
- http://www.bugtraq.ir/adv/t1lib.txt url
- FEDORA-2007-3390 vendor-advisory
- RHSA-2007:1027 vendor-advisory
- MDKSA-2007:230 vendor-advisory
- http://bugs.gentoo.org/show_bug.cgi?id=193437 url
- oval:org.mitre.oval:def:10557 vdb
- php-imagepsloadfont-bo(35620) vdb
- FEDORA-2007-2343 vendor-advisory
…and 21 more