Bug 352271 (CVE-2007-4033)

Summary: CVE-2007-4033 t1lib font filename string overflow
Product: [Other] Security Response Reporter: Mark J. Cox <mjc>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jnovy, kreilly, tcallawa, than
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4033
Whiteboard:
Fixed In Version: 3.0-40.3.fc7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-11-20 18:00:55 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 303021, 356691, 356701, 356711, 356721, 356781, 356791    
Bug Blocks:    

Comment 1 Mark J. Cox 2007-10-25 13:31:58 UTC
        local copy in xpdf and tetex code

        CVE-2007-4033 Maybe Affects: tetex rhel-3
        CVE-2007-4033 Maybe Affects: tetex rhel-4
        CVE-2007-4033 Maybe Affects: tetex rhel-5

        CVE-2007-4033 Maybe Affects: xpdf rhel-2.1
        CVE-2007-4033 Maybe Affects: xpdf rhel-3
        CVE-2007-4033 Doesn't Affect: xpdf rhel-4  (--without-t1-library)

For RHEL5 this will be caught by fortify_source (strcat())

Comment 2 Mark J. Cox 2007-10-25 13:35:26 UTC
patch at http://bugs.gentoo.org/show_bug.cgi?id=193437#c1


Comment 3 Tom "spot" Callaway 2007-10-25 14:02:40 UTC
There's no local copy of t1lib in xpdf (at least not in FC-6, F-7, F-8,
rawhide). We're using the system t1lib.

Comment 9 Fedora Update System 2007-11-15 03:32:23 UTC
tetex-3.0-44.2.fc8 has been pushed to the Fedora 8 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update tetex'

Comment 10 Fedora Update System 2007-11-15 03:46:16 UTC
tetex-3.0-40.3.fc7 has been pushed to the Fedora 7 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update tetex'

Comment 11 Fedora Update System 2007-11-20 18:00:45 UTC
tetex-3.0-40.3.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2007-11-20 18:04:54 UTC
tetex-3.0-44.3.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.