>> PHP GD Graphics Library "gdPngReadData()" PNG File Denial of Service Vulnerability
Title : PHP GD Graphics Library "gdPngReadData()" PNG File Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-1905 CVE ID : CVE-2007-2756
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-22
Technical Description
A vulnerability has been identified in PHP, which could be exploited by attackers to cause a denial of service. This issue is caused by an infinite loop in the "gdPngReadData()" [gd/libgd/gd_png.c] function when processing PNG images with truncated data, which could be exploited by remote attackers to crash a vulnerable web server via a malicious image.