CVE-2007-0455: Buffer Overflow
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0455?
CVE-2007-0455 has a severity rating that indicates it can lead to denial of service and potential arbitrary code execution.
How do I fix CVE-2007-0455?
To fix CVE-2007-0455, upgrade to GD Graphics Library version 2.0.34 or later.
Which systems are vulnerable to CVE-2007-0455?
Systems running GD Graphics Library versions 2.0.33 and earlier, as well as specific versions of PHP and various Linux distributions are vulnerable to CVE-2007-0455.
What type of attack does CVE-2007-0455 enable?
CVE-2007-0455 enables remote attackers to craft strings that may trigger a buffer overflow, causing application crashes.
Is CVE-2007-0455 specific to a certain programming language?
CVE-2007-0455 is primarily associated with the GD Graphics Library but can affect applications written in PHP that utilize this library.