CVE-2007-2756

Publication date 18 May 2007

Last updated 24 July 2024


Ubuntu priority

The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.

Status

Package Ubuntu Release Status
libgd2 7.04 feisty
Fixed 2.0.34~rc1-2ubuntu1.1
6.10 edgy
Fixed 2.0.33-4ubuntu2.1
6.06 LTS dapper
Fixed 2.0.33-2ubuntu5.2

References

Related Ubuntu Security Notices (USN)

    • USN-473-1
    • libgd2 vulnerabilities
    • 12 June 2007

Other references