First published: Thu Jun 28 2007(Updated: )
The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GD Graphics Library | =2.0.34-rc2 | |
GD Graphics Library | =2.0.33 | |
GD Graphics Library | =2.0.34-rc1 | |
GD Graphics Library | =2.0.35-rc3 | |
GD Graphics Library | =2.0.35-rc2 | |
GD Graphics Library | =2.0.35-rc1 | |
GD Graphics Library | <=2.0.35 | |
GD Graphics Library | =2.0.34 | |
GD Graphics Library | =2.0.35-rc4 |
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3477 has been classified as a denial of service vulnerability due to excessive CPU consumption.
To fix CVE-2007-3477, upgrade the GD Graphics Library to version 2.0.35 or later.
CVE-2007-3477 affects versions 2.0.34-rc2, 2.0.34-rc1, 2.0.33, and versions up to and including 2.0.35-rc4.
The vulnerable functions in CVE-2007-3477 are imagearc and imagefilledarc.
CVE-2007-3477 facilitates a denial of service attack through excessive CPU usage.