CVE-2004-0990
libgd2 - integer overflows
EPSS 28.3%
描述
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.
如何修補 CVE-2004-0990
要修補 CVE-2004-0990,請將受影響套件升級到下列已修補版本。
- Debian/libgd—升級至 1.8.4-17.woody3 或更新版本
- Debian/libgd—升級至 1.8.4-17.woody3 或更新版本
- —升級至 2.0.30-1 或更新版本
- —升級至 2.0.1-10woody1 或更新版本
CVE-2004-0990 正在被利用嗎?
中等 — EPSS 為 28.3%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 1.8.4-17.woody3
- from 0, < 1.8.4-17.woody3
- from 0, < 2.0.30-1
- from 0, < 2.0.1-10woody1