From 26d0bc8f27efcb94a2968b587fc4db29ff2c122b Mon Sep 17 00:00:00 2001 From: Xin LI Date: Thu, 5 Nov 2009 21:40:57 +0000 Subject: Document remote buffer overflow vulnerability in gd. --- security/vuxml/vuln.xml | 41 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 708f8c626a59..268426da40a1 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -35,6 +35,47 @@ Note: Please add new entries to the beginning of this file. --> + + gd -- '_gdGetColors' remote buffer overflow vulnerability + + + gd + 0 + + + php5-gd + 0 + + + php4-gd + 0 + + + + +

CVE reports:

+
+

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and + 5.3.0, and the GD Graphics Library 2.x, does not properly + verify a certain colorsTotal structure member, which might + allow remote attackers to conduct buffer overflow or buffer + over-read attacks via a crafted GD file, a different + vulnerability than CVE-2009-3293.

+
+ +
+ + 36712 + CVE-2009-3546 + http://secunia.com/advisories/37069 + http://secunia.com/advisories/37080 + + + 2009-10-15 + 2009-11-05 + +
+ typo3 -- multiple vulnerabilities in TYPO3 Core -- cgit v1.2.3