PT-2007-1096 · Libgd · Gd Graphics Library

Publicado

2007-06-28

·

Atualizado

2018-10-16

·

CVE-2007-3478

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: GD Graphics Library (libgd) versions prior to 2.0.35
Description: The issue is related to a race condition in the gdImageStringFTEx function, specifically in the gdft draw bitmap part of the gdft.c file. This could allow remote attackers to cause a denial of service, potentially by exploiting the library's support for truetype font (TTF) files. Multiple vulnerabilities in the GD Graphics Library package before version 2.0.35 may lead to disruptions in the availability of protected information, and these vulnerabilities can be exploited remotely.
Recommendations: For versions prior to 2.0.35, update to version 2.0.35 or later to resolve the issue. As a temporary workaround, consider restricting the use of truetype font (TTF) support until a patch is applied.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09579
CVE-2007-3478

Produtos afetados

Gd Graphics Library