Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] [USN-515-1] t1lib vulnerability |
|---|---|
| Date: | Fri, 21 Sep 2007 08:19:07 -0700 |
Hi, On Fri, Sep 21, 2007 at 04:30:31PM +0400, 3APA3A wrote:
CVE-2007-4033 is "Buffer overflow in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long argument to the imagepsloadfont function." Please, provide valid CVE entry. --Thursday, September 20, 2007, 12:18:02 AM, you wrote to ubuntu-security-announce@lists.ubuntu.com: KC> =========================================================== KC> Ubuntu Security Notice USN-515-1 September 19, 2007 KC> t1lib vulnerability KC> CVE-2007-4033 KC> ===========================================================
That is the correct CVE -- the true cause of the gd2 issue was in t1lib, not gd2: http://www.securityfocus.com/bid/25079/info -Kees -- Kees Cook
signature.asc
Description: Digital signature
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | List all the comment + entry belong to the Yahoo 360 public blog and more..., vnn95 |
|---|---|
| Next by Date: | Re: [Full-disclosure] 0day: PDF pwns Windows, Chad Perrin |
| Previous by Thread: | Re: [Full-disclosure] [USN-515-1] t1lib vulnerability, Ismail Dönmez |
| Next by Thread: | rPSA-2007-0193-1 gdm, rPath Update Announcements |
| Indexes: | [Date] [Thread] [Top] [All Lists] |