CVE-2007-3476
Summary
| CVE | CVE-2007-3476 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-06-28 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gd Graphics Library | Gdlib | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | fedoranews.org | |
| rPath Update for gd and Multiple php Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for gd - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/37741 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| www.trustix.org/errata/2007/0024 | af854a3a-2127-422b-91ae-364da2661108 | www.trustix.org | |
| ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-... | af854a3a-2127-422b-91ae-364da2661108 | ftp.slackware.com | |
| Gentoo update for gd - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo update for ptex - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mandriva update for gd - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for libwmf - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for gd - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora Core 6 Update: gd-2.0.35-1.fc6 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian update for libgd2 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- CSTeX: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Bug 277421 – CVE-2007-3472 CVE-2007-3473 CVE-2007-3474 CVE-2007-3475 CVE-2007-3476 CVE-2007-3477 CVE-2007-3478 gd various flaws [FC6] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| GD Graphics Library Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Fedora update for gd - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| issues.rpath.com/browse/RPL-1643 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| [SECURITY] Fedora 14 Update: libwmf-0.2.8.4-27.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Trustix Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Slackware update for gd - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| FS#87: fix segfault when an invalid color index is present in the image data | af854a3a-2127-422b-91ae-364da2661108 | bugs.libgd.org | |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Mandriva update for tetex - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ReleaseNote020035 - LibGD | af854a3a-2127-422b-91ae-364da2661108 | www.libgd.org | Patch |
| PTeX: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| GD: Multiple vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Debian -- Security Information -- DSA-1613-1 libgd2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 13 Update: libwmf-0.2.8.4-22.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-09-05 | Mark J Cox | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-3476 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. |
There are currently no legacy QID mappings associated with this CVE.