gd / php-gd ImageCreateFromPng infinite loop caused by truncated PNG
Published May 18, 2007
4.3
MEDIUMCVSS 2.0
EPSS 4.27%
Description
The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
php-0:4.3.2-43.ent
Fixed · RHSA-2007:0889
Red Hat Enterprise Linux 4
gd-0:2.0.28-5.4E.el4_6.1
Fixed · RHSA-2008:0146
Red Hat Enterprise Linux 4
php-0:4.3.9-3.22.9
Fixed · RHSA-2007:0890
Red Hat Enterprise Linux 5
gd-0:2.0.33-9.4.el5_1.1
Fixed · RHSA-2008:0146
Red Hat Enterprise Linux 5
php-0:5.1.6-15.el5
Fixed · RHSA-2007:0890
Red Hat Web Application Stack for RHEL 4
php-0:5.1.6-3.el4s1.8
Fixed · RHSA-2007:0891
Red Hat Enterprise Linux 4
libwmf
Will not fix
Red Hat Enterprise Linux 5
libwmf
Will not fix
Red Hat Enterprise Linux 6
libwmf
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | php-0:4.3.2-43.ent | Fixed | RHSA-2007:0889 |
| Red Hat Enterprise Linux 4 | gd-0:2.0.28-5.4E.el4_6.1 | Fixed | RHSA-2008:0146 |
| Red Hat Enterprise Linux 4 | php-0:4.3.9-3.22.9 | Fixed | RHSA-2007:0890 |
| Red Hat Enterprise Linux 5 | gd-0:2.0.33-9.4.el5_1.1 | Fixed | RHSA-2008:0146 |
| Red Hat Enterprise Linux 5 | php-0:5.1.6-15.el5 | Fixed | RHSA-2007:0890 |
| Red Hat Web Application Stack for RHEL 4 | php-0:5.1.6-3.el4s1.8 | Fixed | RHSA-2007:0891 |
| Red Hat Enterprise Linux 4 | libwmf | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | libwmf | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libwmf | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates for libwmf in Red Hat Enterprise Linux 5 and 6. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.27% (0.04267) | 90.77th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.27% (0.04267) | 89.77th | v5 (v2026.06.15) |
| Aug 11, 2025 | 7.00% (0.06998) | 91.04th | v4 (v2025.03.14) |
| Jul 31, 2025 | 5.04% (0.05038) | 89.34th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.46% (0.06460) | 90.15th | v4 (v2025.03.14) |
| Mar 29, 2025 | 10.10% (0.10095) | 88.39th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.46% (0.06460) | 90.38th | v4 (v2025.03.14) |
| Dec 17, 2024 | 6.45% (0.06447) | 93.63th | v3 (v2023.03.01) |
| Nov 27, 2024 | 10.64% (0.10640) | 95.28th | v3 (v2023.03.01) |
| Aug 21, 2024 | 8.84% (0.08843) | 94.65th | v3 (v2023.03.01) |
| Apr 28, 2024 | 6.44% (0.06444) | 93.62th | v3 (v2023.03.01) |
| Mar 21, 2024 | 5.80% (0.05802) | 93.23th | v3 (v2023.03.01) |
| Feb 12, 2024 | 3.56% (0.03559) | 91.26th | v3 (v2023.03.01) |
| Jan 5, 2024 | 3.04% (0.03040) | 89.96th | v3 (v2023.03.01) |
| Oct 20, 2023 | 2.18% (0.02178) | 88.14th | v3 (v2023.03.01) |
| May 24, 2023 | 2.08% (0.02081) | 87.43th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.52% (0.01515) | 84.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
References (66)
- http://bugs.libgd.org/?do=details&task_id=86 x_refsource_CONFIRMPatch
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795 vendor-advisoryx_refsource_HP
- http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/35788 vdb-entryx_refsource_OSVDB
- http://osvdb.org/36643 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2007-0889.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/25353 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25362 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25378 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25535 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25575 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25590 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25646 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25657 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25658 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25787 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25855 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26048 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26231 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26390 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26871 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26895 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26930 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26967 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27037 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27102 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27110 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27545 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29157 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30168 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200708-05.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200711-34.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200805-13.xml vendor-advisoryx_refsource_GENTOO
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.482863 vendor-advisoryx_refsource_SLACKWARE
- http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm x_refsource_CONFIRM
- http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml vendor-advisoryx_refsource_GENTOO
- http://www.libgd.org/ReleaseNote020035 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:122 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:123 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:124 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:187 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_13_sr.html vendor-advisoryx_refsource_SUSE
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.020.html vendor-advisoryx_refsource_OPENPKG
- http://www.php.net/releases/5_2_3.php x_refsource_CONFIRM
- http://www.redhat.com/support/errata/RHSA-2007-0890.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2007-0891.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0146.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/24089 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1018187 vdb-entryx_refsource_SECTRACK
- http://www.trustix.org/errata/2007/0019/ vendor-advisoryx_refsource_TRUSTIX
- http://www.trustix.org/errata/2007/0023/ vendor-advisoryx_refsource_TRUSTIX
- http://www.ubuntu.com/usn/usn-473-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2007/1904 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/1905 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/2016 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/2336 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/3386 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-2756 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=242033 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34420 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-1394 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-2756
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10779 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2007-2756
- https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.