OpenPKG Corporation
OpenPKG CorporationSecuritySecurity Advisories

OpenPKG Security Advisory

OpenPKG-SA-2004.049

Publisher Name:          OpenPKG GmbH
Publisher Home:          http://openpkg.com/

Advisory Id (public):    OpenPKG-SA-2004.049
Advisory Type:           OpenPKG Security Advisory (SA)
Advisory Directory:      http://openpkg.com/go/OpenPKG-SA
Advisory Document:       http://openpkg.com/go/OpenPKG-SA-2004.049
Advisory Published:      2010-02-09 15:47 UTC

Issue Id (internal):     OpenPKG-SI-20041030.02
Issue First Created:     2004-10-30
Issue Last Modified:     2006-11-28
Issue Revision:          06


Subject Name: gd Subject Summary: Fast Graphics Generation Library Subject Home: http://www.boutell.com/gd/ Subject Versions: * <= 2.0.28 Vulnerability Id: CVE-2004-0990 Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: Attack Impact: denial of service, arbitrary code execution Description: In a BUGTRAQ posting [0], a vulnerability was reported for the graphics library GD [1]. There can be an integer overflow when allocating memory in the routine that handles loading of PNG image files. This later leads to heap data structures being overwritten. If an attacker tricked a user into loading a malicious PNG image, they could leverage this into executing arbitrary code in the context of the user opening the image. Similar integer overflow possibilities also exist in other code parts of GD. References: [0] http://www.securityfocus.com/archive/1/379382 [1] http://www.boutell.com/gd/ [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0990 [3] http://www.openpkg.org/tutorial.html#regular-source [4] http://www.openpkg.org/tutorial.html#regular-binary [5] ftp://ftp.openpkg.org/release/2.2/UPD/gd-2.0.28-2.2.1.src.rpm [6] ftp://ftp.openpkg.org/release/2.1/UPD/gd-2.0.27-2.1.2.src.rpm [7] ftp://ftp.openpkg.org/release/2.2/UPD/ [8] ftp://ftp.openpkg.org/release/2.1/UPD/ [9] http://www.openpkg.org/security.html#signature
Primary Package Name: gd Primary Package Home: http://openpkg.org/go/package/gd Affected Distribution: Affected Branch: Affected Package: OpenPKG Community 2.1-SOLID gd-2.0.27-2.1.1 OpenPKG Community 2.2-SOLID gd-2.0.28-2.2.0 OpenPKG Community CURRENT gd-2.0.28-20041001 Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Community 2.1-SOLID gd-2.0.27-2.1.2 OpenPKG Community 2.2-SOLID gd-2.0.28-2.2.1 OpenPKG Community CURRENT gd-2.0.29-20041030

Latest Advisories:
2007.023 perl
2007.022 bind
2007.021 wordpress
2007.020 php
2007.019 php
2007.018 freetype
2007.017 ratbox
2007.016 gd
2007.015 quagga
2007.014 bind
more...

See Also:
OpenPKG Enterprise 1
ChangeLog!

Validation: XHTML | CSS