RHSA-2008:0146: Moderate: gd security update
The gd package contains a graphics library used for the dynamic creation ofimages such as PNG and JPEG.Multiple issues were discovered in the gd GIF image-handling code. Acarefully-crafted GIF file could cause a crash or possibly execute codewith the privileges of the application using the gd library.(CVE-2006-4484, CVE-2007-3475, CVE-2007-3476)An integer overflow was discovered in the gdImageCreateTrueColor()function, leading to incorrect memory allocations. A carefully craftedimage could cause a crash or possibly execute code with the privileges ofthe application using the gd library. (CVE-2007-3472)A buffer over-read flaw was discovered. This could cause a crash in anapplication using the gd library to render certain strings using aJIS-encoded font. (CVE-2007-0455)A flaw was discovered in the gd PNG image handling code. A truncated PNGimage could cause an infinite loop in an application using the gd library.(CVE-2007-2756)A flaw was discovered in the gd X BitMap (XBM) image-handling code. Amalformed or truncated XBM image could cause a crash in an applicationusing the gd library. (CVE-2007-3473)Users of gd should upgrade to these updated packages, which containbackported patches which resolve these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0146?
The severity of RHSA-2008:0146 is categorized as critical due to potential crashes or arbitrary code execution.
How do I fix RHSA-2008:0146?
To fix RHSA-2008:0146, upgrade the gd package to version 2.0.33-9.4.el5_1.1 or later.
Which packages are affected by RHSA-2008:0146?
Affected packages include gd, gd-devel, and gd-progs in specific versions on Red Hat Enterprise Linux.
Is it safe to use older versions of the gd package after RHSA-2008:0146?
No, using older versions of the gd package after RHSA-2008:0146 poses security risks and should be avoided.
What kind of vulnerabilities does RHSA-2008:0146 address?
RHSA-2008:0146 addresses vulnerabilities in the GIF image-handling code of the gd library that could lead to crashes or code execution.