This script is Copyright (C) 2007-2015 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-200708-05
(GD: Multiple vulnerabilities)
Xavier Roche discovered an infinite loop in the gdPngReadData()
function when processing a truncated PNG file (CVE-2007-2756). An
integer overflow has been discovered in the gdImageCreateTrueColor()
function (CVE-2007-3472). An error has been discovered in the function
gdImageCreateXbm() function (CVE-2007-3473). Unspecified
vulnerabilities have been discovered in the GIF reader (CVE-2007-3474).
An error has been discovered when processing a GIF image that has no
global color map (CVE-2007-3475). An array index error has been
discovered in the file gd_gif_in.c when processing images with an
invalid color index (CVE-2007-3476). An error has been discovered in
the imagearc() and imagefilledarc() functions when processing overly
large angle values (CVE-2007-3477). A race condition has been
discovered in the gdImageStringFTEx() function (CVE-2007-3478).
A remote attacker could exploit one of these vulnerabilities to cause a
Denial of Service or possibly execute arbitrary code with the
privileges of the user running GD.
There is no known workaround at this time.
See also :
All GD users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=media-libs/gd-2.0.35'
Risk factor :
Medium / CVSS Base Score : 5.0
Family: Gentoo Local Security Checks
Nessus Plugin ID: 25870 (gentoo_GLSA-200708-05.nasl)
CVE ID: CVE-2007-2756CVE-2007-3472CVE-2007-3473CVE-2007-3474CVE-2007-3475CVE-2007-3476CVE-2007-3477CVE-2007-3478
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.