CVE-2007-3472: Integer Overflow
Published Jun 28, 2007
·Updated
Integer overflow in gdImageCreateTrueColor function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to have unspecified attack vectors and impact.
Affected Software
9 affected components
Libgd GD Graphics Library=2.0.34-rc2
Libgd GD Graphics Library=2.0.33
Libgd GD Graphics Library=2.0.34-rc1
Libgd GD Graphics Library=2.0.35-rc3
Libgd GD Graphics Library=2.0.35-rc2
Libgd GD Graphics Library=2.0.35-rc1
Libgd GD Graphics Library<=2.0.35
Libgd GD Graphics Library=2.0.34
Libgd GD Graphics Library=2.0.35-rc4
Event History
Jun 28, 2007
CVE Published
06:30 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3472?
CVE-2007-3472 is classified as having a potentially high severity due to its integer overflow vulnerability in the GD Graphics Library.
2
How do I fix CVE-2007-3472?
To fix CVE-2007-3472, you should upgrade to GD Graphics Library version 2.0.36 or later.
3
Which versions of the GD Graphics Library are affected by CVE-2007-3472?
CVE-2007-3472 affects GD Graphics Library versions up to and including 2.0.35.
4
What is the impact of CVE-2007-3472?
The impact of CVE-2007-3472 may allow user-assisted remote attackers to exploit the vulnerability through unspecified attack vectors.
5
Is CVE-2007-3472 still a concern for current systems?
CVE-2007-3472 remains a concern for systems using affected versions of the GD Graphics Library that have not been updated.