CVE-2004-0990

GD Graphics Library libgd 2.0.28 - RCE/DoS

Title source: llm

Description

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · clocallinux
https://www.exploit-db.com/exploits/600

References (26)

... and 6 more

Scores

EPSS 0.2121
EPSS Percentile 95.7%

Details

Status published
Products (24)
gd_graphics_library/gdlib 1.8.4
gd_graphics_library/gdlib 2.0.1
gd_graphics_library/gdlib 2.0.15
gd_graphics_library/gdlib 2.0.20
gd_graphics_library/gdlib 2.0.21
gd_graphics_library/gdlib 2.0.22
gd_graphics_library/gdlib 2.0.23
gd_graphics_library/gdlib 2.0.26
gd_graphics_library/gdlib 2.0.27
gd_graphics_library/gdlib 2.0.28
... and 14 more
Published Mar 01, 2005
Tracked Since Feb 18, 2026