Jump to content

Advisories MDVSA-2009:284-1: gd


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in gd:

 

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.0, and the

GD Graphics Library 2.x, does not properly verify a certain colorsTotal

structure member, which might allow remote attackers to conduct

buffer overflow or buffer over-read attacks via a crafted GD file,

a different vulnerability than CVE-2009-3293. NOTE: some of these

details are obtained from third party information (CVE-2009-3546).

 

This update fixes this vulnerability.

 

Update:

 

Packages for 2008.0 are being provided due to extended support for

Corporate products.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...