CVE-2007-3477: Medium severity Libgd GD Graphics Library vulnerability
Published Jun 28, 2007
·Updated
The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value.
Affected Software
9 affected components
Libgd GD Graphics Library=2.0.34-rc2
Libgd GD Graphics Library=2.0.33
Libgd GD Graphics Library=2.0.34-rc1
Libgd GD Graphics Library=2.0.35-rc3
Libgd GD Graphics Library=2.0.35-rc2
Libgd GD Graphics Library=2.0.35-rc1
Libgd GD Graphics Library<=2.0.35
Libgd GD Graphics Library=2.0.34
Libgd GD Graphics Library=2.0.35-rc4
Remediation
Patch Available
Event History
Jun 28, 2007
CVE Published
06:30 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3477?
CVE-2007-3477 has been classified as a denial of service vulnerability due to excessive CPU consumption.
2
How do I fix CVE-2007-3477?
To fix CVE-2007-3477, upgrade the GD Graphics Library to version 2.0.35 or later.
3
Which versions of GD Graphics Library are affected by CVE-2007-3477?
CVE-2007-3477 affects versions 2.0.34-rc2, 2.0.34-rc1, 2.0.33, and versions up to and including 2.0.35-rc4.
4
What functions are vulnerable in CVE-2007-3477?
The vulnerable functions in CVE-2007-3477 are imagearc and imagefilledarc.
5
What type of attack does CVE-2007-3477 facilitate?
CVE-2007-3477 facilitates a denial of service attack through excessive CPU usage.