CVE-2007-3478: Race Condition
Published Jun 28, 2007
·Updated
Race condition in gdImageStringFTEx (gdftdrawbitmap) in gdft.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors, possibly involving truetype font (TTF) support.
Affected Software
1 affected component
GD Graphics Library Gdlib<=2.0.34
Event History
Jun 28, 2007
CVE Published
06:30 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3478?
CVE-2007-3478 is classified as a denial of service vulnerability.
2
How do I fix CVE-2007-3478?
To fix CVE-2007-3478, upgrade the GD Graphics Library to version 2.0.35 or later.
3
What components are affected by CVE-2007-3478?
CVE-2007-3478 affects the GD Graphics Library (libgd) versions prior to 2.0.35.
4
What type of attack does CVE-2007-3478 enable?
CVE-2007-3478 enables user-assisted remote attackers to cause a denial of service.
5
Which specific function is vulnerable in CVE-2007-3478?
The vulnerable function in CVE-2007-3478 is gdImageStringFTEx in gdft.c.