Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50446
Category:Ubuntu Local Security Checks
Title:Ubuntu 4.10 USN-11-1 (libgd2)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to libgd2
announced via advisory USN-11-1.

Several buffer overflows have been discovered in libgd's PNG handling
functions.

If an attacker tricked a user into loading a malicious PNG image, they
could leverage this into executing arbitrary code in the context of
the user opening image. Most importantly, this library is commonly
used in PHP. One possible target would be a PHP driven photo website
that lets users upload images. Therefore this vulnerability might lead
to privilege escalation to a web server's privileges.

The following packages are affected:

libgd2-xpm
libgd2-noxpm

Solution:
The problem can be corrected by upgrading the affected packages to
version 2.0.23-2ubuntu0.1. In general, a standard system upgrade is
sufficient to effect the necessary changes.
http://lists.ubuntu.com/archives/ubuntu-security-announce/2004-October/000013.html

Risk factor : High

CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.