Back

MEDIUM

libgd Denial of service by corrupted GIF images

Published Jun 28, 2007

Description

Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.

Affected products

Remediation

Red Hat statement

Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-3476 The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw.

Metrics

Weaknesses (1)

References (39)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 28, 2007
Updated Aug 7, 2024
Reserved Jun 28, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jun 21, 2007