First published: Thu Jun 28 2007(Updated: )
Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GD Graphics Library | <=2.0.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3476 has a medium severity rating due to its potential to cause denial of service via segmentation faults.
To fix CVE-2007-3476, upgrade the GD Graphics Library (libgd) to version 2.0.35 or later.
CVE-2007-3476 can cause crashes and heap corruption when processing specially crafted images with large color index values.
CVE-2007-3476 affects all versions of GD Graphics Library before 2.0.35.
Yes, CVE-2007-3476 is considered exploitable by remote attackers if they can trick users into opening malicious image files.