Bug 194520 - CVE-2006-2906 gd denial of service
Summary: CVE-2006-2906 gd denial of service
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: gd   
(Show other bugs)
Version: 5
Hardware: All
OS: Linux
medium
low
Target Milestone: ---
Assignee: Radek Vokal
QA Contact:
URL:
Whiteboard: impact=low,source=bugtraq,reported=20...
Keywords: Security
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-06-08 18:00 UTC by Josh Bressers
Modified: 2007-11-30 22:11 UTC (History)
0 users

Fixed In Version: 2.0.33-9
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2006-07-11 08:09:25 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Testcase based on the C in the bugtraq mail. (9.51 KB, application/x-gzip)
2006-06-08 18:03 UTC, Josh Bressers
no flags Details

Description Josh Bressers 2006-06-08 18:00:21 UTC
gd denial of service

A flaw was found in the way gd loads certain malformed GIF images.  If
a user loads a broken GIF image it is possible to cause gd to enter an
infinite loop.

There is more information in the bugtraq mail:
http://www.securityfocus.com/archive/1/436132


This issue also affects FC4

Comment 1 Josh Bressers 2006-06-08 18:03:25 UTC
Created attachment 130771 [details]
Testcase based on the C in the bugtraq mail.

This testcase doesn't seem to crash when loading a gif image via a file stream,
but does when the data is loaded via a pointer.


Note You need to log in before you can comment on or make changes to this bug.