|
|
GD Graphics Library "_gdGetColors()" Buffer Overflow Vulnerability
|
A vulnerability has been identified in GD Graphics Library, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error in the "_gdGetColors()" [gd_gd.c] function that does not properly check max colors while loading a gd2 palette image, which could allow attackers to crash an affected application or execute arbitrary code via a specially crafted GD file.
GD Graphics Library versions 2.x
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2009/2929 http://www.openwall.com/lists/oss-security/2009/10/15/13
Vulnerability reported by Tomas Hoger.
2009-10-16 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|