CVE-2007-0455
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 11.86% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- gd graphics library project/gd graphics library · php/php · canonical/ubuntu linux · fedoraproject/fedora · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607Issue Tracking, Third Party Advisory
- http://fedoranews.org/cms/node/2631Broken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.htmlMailing List, Third Party Advisory
- http://lists.rpath.com/pipermail/security-announce/2007-February/000145.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2007-0155.htmlThird Party Advisory
- http://secunia.com/advisories/23916Not Applicable, Vendor Advisory
- http://secunia.com/advisories/24022Not Applicable
- http://secunia.com/advisories/24052Not Applicable
- http://secunia.com/advisories/24053Not Applicable
- http://secunia.com/advisories/24107Not Applicable
- http://secunia.com/advisories/24143Not Applicable
- http://secunia.com/advisories/24151Not Applicable
- http://secunia.com/advisories/24924Not Applicable
- http://secunia.com/advisories/24945Not Applicable
- http://secunia.com/advisories/24965Not Applicable
- http://secunia.com/advisories/25575Not Applicable
- http://secunia.com/advisories/29157Not Applicable
- http://secunia.com/advisories/42813Not Applicable
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:035Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:036Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:038Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:109Broken Link
- http://www.redhat.com/support/errata/RHSA-2007-0153.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0162.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0146.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/466166/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/22289Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2007/0007Broken Link
- http://www.ubuntu.com/usn/usn-473-1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.