CVE-2007-3476

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 28 Jun 2007, 18:00
Last modified:07 Aug 2024, 14:21

Vulnerability Summary

Overall Risk (default)
low
19/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
7.95% LOW
8% probability +2.83%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 Jun 2007, 18:00
Published
Vulnerability first disclosed
07 Aug 2024, 14:21
Last Modified
Vulnerability information updated

Description

Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 7.95% Percentile: 92%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • gd_graphics_librarygdlib

    ≤ 2.0.34

References (35)