GD Graphics Library PNG File Processing Denial of Service Vulnerability
BID:24089
Info
GD Graphics Library PNG File Processing Denial of Service Vulnerability
| Bugtraq ID: | 24089 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-2756 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2007 12:00AM |
| Updated: | Mar 19 2015 08:10AM |
| Credit: | Xavier Roche is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux FUJI Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux FUJI 0 Turbolinux Appliance Server 2.0 Trustix Secure Linux 3.0.5 Trustix Secure Linux 3.0 Trustix Secure Linux 2.0 Trustix Operating System Enterprise Server 2.0 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 Slackware Linux 10.2 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Application Stack v1 for Enterprise Linux ES 4 RedHat Application Stack v1 for Enterprise Linux AS 4 Red Hat Fedora Core6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux 5 Server pTeX pTeX 3.1.10 PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 4.4.7 PHP PHP 5.2 OpenPKG OpenPKG E1.0-Solid OpenPKG OpenPKG Current Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux GD Graphics Library gdlib 2.0.34 GD Graphics Library gdlib 2.0.33 CSTeX cstetex 2.0.2 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX 2.0 Avaya Intuity LX 2.0 Avaya Intuity LX Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.4 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 4.0 Avaya Aura Application Enablement Services 3.1 Avaya Aura Application Enablement Services 3.0 |
| Not Vulnerable: |
PHP PHP 5.2.3 |
Discussion
GD Graphics Library PNG File Processing Denial of Service Vulnerability
The GD graphics library is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions in applications implementing the affected library.
GD graphics library 2.0.34 is reported vulnerable; other versions may be affected as well.
The GD graphics library is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions in applications implementing the affected library.
GD graphics library 2.0.34 is reported vulnerable; other versions may be affected as well.
Exploit / POC
GD Graphics Library PNG File Processing Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GD Graphics Library PNG File Processing Denial of Service Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Slackware Linux -current
PHP PHP 5.2
Slackware Linux 10.2
PHP PHP 5.2.1
PHP PHP 5.2.2
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Slackware Linux -current
-
Slackware php-5.2.3-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/ph p-5.2.3-i486-1.tgz
PHP PHP 5.2
-
PHP PHP 5.2.3
http://www.php.net/downloads.php#v5
Slackware Linux 10.2
-
Slackware php-5.2.3-i486-1_slack10.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/testing/packages/ php5/php-5.2.3-i486-1_slack10.2.tgz
PHP PHP 5.2.1
-
PHP PHP 5.2.3
http://www.php.net/downloads.php#v5
PHP PHP 5.2.2
-
PHP PHP 5.2.3
http://www.php.net/downloads.php#v5
References
GD Graphics Library PNG File Processing Denial of Service Vulnerability
References:
References:
- ChangeLog Version 5.2.3 (PHP)
- FS#86 �?? Possible infinite loop in libgd/gd_png.c (inside png_set_read_fn() callb (GD Graphics Library)
- gdlib Home Page (GD Graphics Library)
- PHP CVS Repository (PHP)
- ASA-2007-449 PHP security updates (RHSA-2007-0888, RHSA-2007-0889 & RHSA-2007-08 (Avaya)
- ASA-2008-099 - gd security update (RHSA-2008-0146) (Avaya)
- RHSA-2007:0889-5 php security update (Red Hat)
- RHSA-2007:0890-2 php security update (Red Hat)
- RHSA-2007:0891-5 php security update (Red Hat)
- RHSA-2008:0146-2 - gd security update (Red Hat)