CVE-2007-3476: Medium severity GD Graphics Library Gdlib vulnerability
Array index error in gdgifin.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3476?
CVE-2007-3476 has a medium severity rating due to its potential to cause denial of service via segmentation faults.
How do I fix CVE-2007-3476?
To fix CVE-2007-3476, upgrade the GD Graphics Library (libgd) to version 2.0.35 or later.
What damage can CVE-2007-3476 cause?
CVE-2007-3476 can cause crashes and heap corruption when processing specially crafted images with large color index values.
Which versions of GD Graphics Library are affected by CVE-2007-3476?
CVE-2007-3476 affects all versions of GD Graphics Library before 2.0.35.
Is CVE-2007-3476 exploitable remotely?
Yes, CVE-2007-3476 is considered exploitable by remote attackers if they can trick users into opening malicious image files.