CVE-2009-3050
Publication date 2 September 2009
Last updated 24 July 2024
Ubuntu priority
Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries.
Status
Package | Ubuntu Release | Status |
---|---|---|
htmldoc | ||
Notes
mdeslaur
PoC: http://packetstormsecurity.org/0907-exploits/htmldoc-overflow.txt other PoC: http://milw0rm.com/exploits/9190 stack smashing is detected by hardy+, so setting priority to low
Patch details
Package | Patch details |
---|---|
htmldoc |