SUSE-SR:2006:003Vendor advisory
http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html CVE-2004-0990
GD Graphics Library - Local Heap Overflow
Record summary
CVE-2004-0990 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGD Graphics Library - Local Heap OverflowExploitDB exploitby anonymousNot analyzed1 file
References
Showing 12 of 2720041026 libgd integer overflowmailing list
http://marc.info/?l=bugtraq&m=109882489302099&w=2 18717Third-party advisory
http://secunia.com/advisories/18717 20824Third-party advisory
http://secunia.com/advisories/20824 20866Third-party advisory
http://secunia.com/advisories/20866 21050Third-party advisory
http://secunia.com/advisories/21050 23783Third-party advisory
http://secunia.com/advisories/23783 P-071Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/p-071.shtml DSA-589Vendor advisory
http://www.debian.org/security/2004/dsa-589 DSA-591Vendor advisory
http://www.debian.org/security/2004/dsa-591 DSA-601Vendor advisory
http://www.debian.org/security/2004/dsa-601 DSA-602Vendor advisory
http://www.debian.org/security/2004/dsa-602