CVE-2007-2756

Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 18 May 2007, 18:00
Last modified:07 Aug 2024, 13:49

Vulnerability Summary

Overall Risk (default)
low
19/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
6.83% LOW
7% probability -0.29%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 May 2007, 18:00
Published
Vulnerability first disclosed
07 Aug 2024, 13:49
Last Modified
Vulnerability information updated

Description

The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 6.83% Percentile: 92%

Affected Systems

  • libgdlibgd

    2.0.34

References (62)