CVE-2004-0990: Buffer Overflow
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0990?
CVE-2004-0990 is classified as a high severity vulnerability due to its potential for denial of service and arbitrary code execution.
How do I fix CVE-2004-0990?
To fix CVE-2004-0990, update to a secure version of the GD Graphics Library, specifically libgd2 version 2.0.33-2ubuntu5.2 or later.
Which versions of libgd are affected by CVE-2004-0990?
CVE-2004-0990 affects libgd versions 1.8.4 and 2.0.28, among others.
Is CVE-2004-0990 applicable to any software aside from libgd?
CVE-2004-0990 primarily impacts the GD Graphics Library, particularly its handling of PNG files.
What kind of attacks are possible due to CVE-2004-0990?
Exploiting CVE-2004-0990 may lead to denial of service attacks or the execution of arbitrary code by sending crafted PNG images.