Oval Definition:oval:com.redhat.rhsa:def:20080146
Revision Date:2008-02-28Version:635
Title:RHSA-2008:0146: gd security update (Moderate)
Description:The gd package contains a graphics library used for the dynamic creation of images such as PNG and JPEG.

  • Multiple issues were discovered in the gd GIF image-handling code. A carefully-crafted GIF file could cause a crash or possibly execute code with the privileges of the application using the gd library. (CVE-2006-4484, CVE-2007-3475, CVE-2007-3476)

  • An integer overflow was discovered in the gdImageCreateTrueColor() function, leading to incorrect memory allocations. A carefully crafted image could cause a crash or possibly execute code with the privileges of the application using the gd library. (CVE-2007-3472)

  • A buffer over-read flaw was discovered. This could cause a crash in an application using the gd library to render certain strings using a JIS-encoded font. (CVE-2007-0455)

  • A flaw was discovered in the gd PNG image handling code. A truncated PNG image could cause an infinite loop in an application using the gd library. (CVE-2007-2756)

  • A flaw was discovered in the gd X BitMap (XBM) image-handling code. A malformed or truncated XBM image could cause a crash in an application using the gd library. (CVE-2007-3473)

    Users of gd should upgrade to these updated packages, which contain backported patches which resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-4484
    CVE-2007-0455
    CVE-2007-2756
    CVE-2007-3472
    CVE-2007-3473
    CVE-2007-3475
    CVE-2007-3476
    RHSA-2008:0146
    RHSA-2008:0146-01
    RHSA-2008:0146-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • gd is earlier than 0:2.0.28-5.4E.el4_6.1
  • AND gd is signed with Red Hat redhatrelease2 key
  • gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1
  • AND gd-devel is signed with Red Hat redhatrelease2 key
  • gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1
  • AND gd-progs is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • gd is earlier than 0:2.0.33-9.4.el5_1.1
  • AND gd is signed with Red Hat redhatrelease2 key
  • gd-devel is earlier than 0:2.0.33-9.4.el5_1.1
  • AND gd-devel is signed with Red Hat redhatrelease2 key
  • gd-progs is earlier than 0:2.0.33-9.4.el5_1.1
  • AND gd-progs is signed with Red Hat redhatrelease2 key
  • BACK