Publisher Name: OpenPKG GmbH Publisher Home: http://openpkg.com/ Advisory Id (public): OpenPKG-SA-2004.049 Advisory Type: OpenPKG Security Advisory (SA) Advisory Directory: http://openpkg.com/go/OpenPKG-SA Advisory Document: http://openpkg.com/go/OpenPKG-SA-2004.049 Advisory Published: 2008-11-21 21:43 UTC Issue Id (internal): OpenPKG-SI-20041030.02 Issue First Created: 2004-10-30 Issue Last Modified: 2006-11-28 Issue Revision: 06
Subject Name: gd Subject Summary: Fast Graphics Generation Library Subject Home: http://www.boutell.com/gd/ Subject Versions: * <= 2.0.28 Vulnerability Id: CVE-2004-0990 Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: Attack Impact: denial of service, arbitrary code execution Description: In a BUGTRAQ posting [0], a vulnerability was reported for the graphics library GD [1]. There can be an integer overflow when allocating memory in the routine that handles loading of PNG image files. This later leads to heap data structures being overwritten. If an attacker tricked a user into loading a malicious PNG image, they could leverage this into executing arbitrary code in the context of the user opening the image. Similar integer overflow possibilities also exist in other code parts of GD. References: [0] http://www.securityfocus.com/archive/1/379382 [1] http://www.boutell.com/gd/ [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0990 [3] http://www.openpkg.org/tutorial.html#regular-source [4] http://www.openpkg.org/tutorial.html#regular-binary [5] ftp://ftp.openpkg.org/release/2.2/UPD/gd-2.0.28-2.2.1.src.rpm [6] ftp://ftp.openpkg.org/release/2.1/UPD/gd-2.0.27-2.1.2.src.rpm [7] ftp://ftp.openpkg.org/release/2.2/UPD/ [8] ftp://ftp.openpkg.org/release/2.1/UPD/ [9] http://www.openpkg.org/security.html#signature
Primary Package Name: gd Primary Package Home: http://openpkg.org/go/package/gd Affected Distribution: Affected Branch: Affected Package: OpenPKG Community 2.1-SOLID gd-2.0.27-2.1.1 OpenPKG Community 2.2-SOLID gd-2.0.28-2.2.0 OpenPKG Community CURRENT gd-2.0.28-20041001 Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Community 2.1-SOLID gd-2.0.27-2.1.2 OpenPKG Community 2.2-SOLID gd-2.0.28-2.2.1 OpenPKG Community CURRENT gd-2.0.29-20041030