| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.801122 |
| Category: | Buffer overflow |
| Title: | GD Graphics Library '_gdGetColors()' Buffer Overflow Vulnerability (Linux) |
| Summary: | Check for the version of GD Graphics Library |
| Description: | Overview: The host is installed with GD Graphics Library and is prone to Buffer Overflow vulnerability. Vulnerability Insight: The flaw is due to error in '_gdGetColors' function in gd_gd.c which fails to check certain colorsTotal structure member, whicn can be exploited to cause buffer overflow or buffer over-read attacks via a crafted GD file. Impact: Successful exploitation could allow attackers to potentially compromise a vulnerable system. Impact Level: System Affected Software/OS: GD Graphics Library version 2.x on Linux. Fix: No solution or patch is available as of 23rd October, 2009. Information regarding this issue will be updated once the solution details are available. For updates refer to http://www.boutell.com/gd/ References: http://secunia.com/advisories/37069/ http://www.vupen.com/english/advisories/2009/2929 http://marc.info/?l=oss-security&m=125562113503923&w=2 |
| Cross-Ref: |
BugTraq ID: 36712 Common Vulnerability Exposure (CVE) ID: CVE-2009-3546 http://marc.info/?l=oss-security&m=125562113503923&w=2 http://www.openwall.com/lists/oss-security/2009/11/20/5 http://www.mandriva.com/security/advisories?name=MDVSA-2009:285 http://www.redhat.com/support/errata/RHSA-2010-0003.html http://www.securityfocus.com/bid/36712 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11199 http://secunia.com/advisories/37069 http://secunia.com/advisories/37080 http://secunia.com/advisories/38055 http://www.vupen.com/english/advisories/2009/2929 http://www.vupen.com/english/advisories/2009/2930 |
| Copyright | Copyright (C) 2009 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|