PT-2004-3719 · Gd · Gd-Devel+6

Infamous41Md

·

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2004-0990

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GD Graphics Library version 2.0.28 libgd2 versions 1.8.4 and possibly other versions gd-devel versions 1.8.4 gd-progs versions 1.8.4 libgd1-noxpm versions 1.8.4 libgd1 versions 1.8.4 gd versions 1.8.4
Description The issue is related to multiple vulnerabilities in the GD Graphics Library, which can be exploited remotely. This can lead to a denial of service and potentially allow the execution of arbitrary code via PNG image files with large image rows values, causing a heap-based buffer overflow in the gdImageCreateFromPngCtx function. The vulnerabilities can also lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For version 2.0.28, consider updating to a newer version to mitigate the risk. For libgd2 versions 1.8.4, update to a newer version to resolve the issue. For gd-devel versions 1.8.4, update to a newer version to resolve the issue. For gd-progs versions 1.8.4, update to a newer version to resolve the issue. For libgd1-noxpm versions 1.8.4, update to a newer version to resolve the issue. For libgd1 versions 1.8.4, update to a newer version to resolve the issue. For gd versions 1.8.4, update to a newer version to resolve the issue. As a temporary workaround, consider disabling the gdImageCreateFromPngCtx function until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03349
BDU:2015-03350
BDU:2015-06180
BDU:2015-06181
BDU:2015-06182
CVE-2004-0990
DSA-589-1
DSA-591-1
DSA-601-1
DSA-602-1
RHSA-2004:638

Affected Products

Gd Graphics Library
Gd
Gd-Devel
Gd-Progs
Libgd1
Libgd1-Noxpm
Libgd2