Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade media-libs/t1lib. | Oct 30, 2017 | Jul 27, 2007 |
| Php | — | Upgrade to PHP version 5.2.4 | Oct 1, 2012 | Jul 27, 2007 |
| Suse | — | Upgrade t1libUpgrade suse-releaseUpgrade t1lib-devel | Feb 17, 2015 | Jul 27, 2007 |
| Ubuntu | — | Upgrade libt1-5 | Nov 8, 2024 | Jul 27, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub