Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T01:17:03.590Z
Reserved: 2009-09-02T00:00:00Z
Link: CVE-2009-3050

No data.

Status : Deferred
Published: 2009-09-02T17:30:01.313
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-3050
