CVE Reference: CVE-2006-2906

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-2906

Description:
The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.0.33 allows remote attackers to cause a denial of service (CPU consumption) via malformed GIF data that causes an infinite loop.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/26976

UBUNTU
  http://www.ubuntulinux.org/support/documentation/usn/usn-298-1

TRUSTIX
  http://www.trustix.org/errata/2006/0038

SUSE
  http://www.novell.com/linux/security/advisories/2006_31_php.html

SREASON
  http://securityreason.com/securityalert/1067

SAID
  Secunia Advisory: SA20676
  Secunia Advisory: SA23783
  Secunia Advisory: SA21186
  Secunia Advisory: SA21050
  Secunia Advisory: SA20866
  Secunia Advisory: SA20887
  Secunia Advisory: SA20853
  Secunia Advisory: SA20571
  Secunia Advisory: SA20500

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:112
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:113

DEBIAN
  http://www.debian.org/security/2006/dsa-1117

CONFIRM

BUGTRAQ
  http://www.securityfocus.com/archive/1/436132

BID
  18294


Return to the previous page.