CVE-2007-2756

Impact:
Low
Public Date:
2007-05-16
CWE:
CWE-835
Bugzilla:
242033: CVE-2007-2756 gd / php-gd ImageCreateFromPng infinite loop caused by truncated PNG

The MITRE CVE dictionary describes this issue as:

The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.

Find out more about CVE-2007-2756 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates for libwmf in Red Hat Enterprise Linux 5 and 6. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (gd) RHSA-2008:0146 2008-02-28
Red Hat Enterprise Linux 4 (php) RHSA-2007:0890 2007-09-20
Red Hat Application Stack v1 for Enterprise Linux AS (v.4) (php) RHSA-2007:0891 2007-10-25
Red Hat Enterprise Linux 3 (php) RHSA-2007:0889 2007-09-26
Red Hat Enterprise Linux 4 (gd) RHSA-2008:0146 2008-02-28
Red Hat Enterprise Linux 5 (php) RHSA-2007:0890 2007-09-20

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 6 libwmf Will not fix
Red Hat Enterprise Linux 5 libwmf Will not fix
Red Hat Enterprise Linux 4 libwmf Will not fix
Unless explicitly stated as not affected, all previous versions of packages in any minor update stream of a product listed here should be assumed vulnerable, although may not have been subject to full analysis.
Last Modified

CVE description copyright © 2017, The MITRE Corporation