Upstream information

CVE-2004-0990 at MITRE

Description

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 10
Vector AV:N/AC:L/Au:N/C:C/I:C/A:C
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entries: 138007 [RESOLVED / FIXED], 62666 [RESOLVED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE LINUX 10.0
  • gd >= 2.0.32-7.2
  • gd-devel >= 2.0.32-7.2
SUSE LINUX 9.1 for IA32
SUSE LINUX 9.1 for x86-64
  • gd >= 2.0.22-65.9
  • gd-devel >= 2.0.22-65.9
SUSE LINUX 9.2
  • gd >= 2.0.28-2.5
  • gd-devel >= 2.0.28-2.5
SUSE LINUX 9.3
  • gd >= 2.0.32-6.2
  • gd-devel >= 2.0.32-6.2
Open Enterprise Server
  • gd >= 2.0.22-65.9
  • gd-devel >= 2.0.22-65.9
core9.x86
core9.ppc
core9.x86-64
core9.ia64
core9.s390
YOU Patch Nr: 10832