Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-09-02T17:00:00Z
Updated: 2024-09-17T01:17:03.590Z
Reserved: 2009-09-02T00:00:00Z
Link: CVE-2009-3050
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-09-02T17:30:01.313
Modified: 2024-11-21T01:06:24.833
Link: CVE-2009-3050
Redhat