                  Buffer overlow vulnerability in htmldoc
                             14 September 2009


Product:           htmldoc
Publisher:         Mandriva
Operating System:  Mandriva
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2009-3050  

Original Bulletin: 

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Mandriva. It is recommended that administrators
         running htmldoc check for an updated version of the software for 
         their operating system.

 Mandriva Linux Security Advisory                         MDVSA-2009:231

 Package : htmldoc
 Date    : September 11, 2009
 Affected: 2009.0, 2009.1, Corporate 4.0

 Problem Description:

 A security vulnerability has been identified and fixed in htmldoc:
 Buffer overflow in the set_page_size function in util.cxx in HTMLDOC
 1.8.27 and earlier allows context-dependent attackers to execute
 arbitrary code via a long MEDIA SIZE comment.  NOTE: it was later
 reported that there were additional vectors in htmllib.cxx and
 ps-pdf.cxx using an AFM font file with a long glyph name, but these
 vectors do not cross privilege boundaries (CVE-2009-3050).
 This update provides a solution to this vulnerability.



 Updated Packages:

