CVE-2007-3474

Published Jun 28, 2007

Last updated 6 years ago

Overview

Description
Multiple unspecified vulnerabilities in the GIF reader in the GD Graphics Library (libgd) before 2.0.35 have unspecified impact and user-assisted remote attack vectors.
Source
cve@mitre.org
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
2.6
Impact score
2.9
Exploitability score
4.9
Vector string
AV:N/AC:H/Au:N/C:N/I:N/A:P

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Evaluator

Comment
-
Impact
An integer overflow exists in the "gdImageCreateTrueColor()" function.
Solution
An integer overflow exists in the "gdImageCreateTrueColor()" function.

Vendor comments

  • Red HatThis issue did not affect the versions of gd as shipped with Red Hat Enterprise Linux 2.1 or 3 as they did not offer GIF image support. We do not plan to backport a fix for this issue to the gd packages as shipped in Red Hat Enterprise Linux 4 and 5 due to the low likelihood of an application affected by this problem being exposed in a way that would allow a trust boundary to be crossed.

Configurations

References