PT-2004-3718 · Gd+1 · Gd-Devel+6

Publicado

1970-01-01

·

Atualizado

2018-05-03

·

CVE-2004-0941

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libgd versions 2.0.21 and earlier gd-devel versions 1.8.4 and earlier gd-progs versions 1.8.4 and earlier libgd1-noxpm versions 1.8.4 and earlier libgd1 versions 1.8.4 and earlier gd versions 1.8.4 and earlier
Description The issue is related to multiple buffer overflows in the gd graphics library, which may allow remote attackers to execute arbitrary code via malformed image files. This is due to improper calls to the gdMalloc function. The vulnerability can be exploited remotely and may lead to disruption of confidentiality, integrity, and availability of protected information.
Recommendations For libgd versions 2.0.21 and earlier, update to a version later than 2.0.21 to resolve the issue. For gd-devel versions 1.8.4 and earlier, update to a version later than 1.8.4 to resolve the issue. For gd-progs versions 1.8.4 and earlier, update to a version later than 1.8.4 to resolve the issue. For libgd1-noxpm versions 1.8.4 and earlier, update to a version later than 1.8.4 to resolve the issue. For libgd1 versions 1.8.4 and earlier, update to a version later than 1.8.4 to resolve the issue. For gd versions 1.8.4 and earlier, update to a version later than 1.8.4 to resolve the issue. As a temporary workaround, consider restricting access to the gdMalloc function until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03349
BDU:2015-03350
BDU:2015-06180
BDU:2015-06181
BDU:2015-06182
CVE-2004-0941
DSA-601-1
DSA-602-1
RHSA-2004:638
RHSA-2006:0194
RHSA-2006_0194

Produtos afetados

Red Hat
Gd
Gd-Devel
Gd-Progs
Libgd
Libgd1
Libgd1-Noxpm