CVE-2007-4033 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 18.7% (pctl 97)
Patch early
A public exploit exists.
Description
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 18.66% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-07-27 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| php | php |
| t1lib | t1lib |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | T1lib - 'intT1_Env_GetCompletePath' Buffer Overflow (PoC) | 2007-07-26 |
| exploit-db | PHP 5.2.3 - 'PHP_gd2.dll' imagepsloadfont Local Buffer Overflow (PoC) | 2007-07-26 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=193437
- http://fedoranews.org/updates/FEDORA-2007-234.shtml
- http://secunia.com/advisories/26241
- http://secunia.com/advisories/26901
- http://secunia.com/advisories/26981
- http://secunia.com/advisories/26992
- http://secunia.com/advisories/27239
- http://secunia.com/advisories/27297
- http://secunia.com/advisories/27439
- http://secunia.com/advisories/27599
- http://secunia.com/advisories/27718
- http://secunia.com/advisories/27743
- http://secunia.com/advisories/28345
- http://secunia.com/advisories/30168
- http://security.gentoo.org/glsa/glsa-200710-12.xml
- http://security.gentoo.org/glsa/glsa-200711-34.xml
- http://security.gentoo.org/glsa/glsa-200805-13.xml
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0007
- http://www.bugtraq.ir/adv/t1lib.txt
- http://www.debian.org/security/2007/dsa-1390
→ the Explorer · watch your stack · NVD