Mandrake Linux Security Advisory : gd (MDKSA-2006:112)
Medium Nessus Plugin ID 21769
SynopsisThe remote Mandrake Linux host is missing one or more security updates.
DescriptionThe LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.0.33 allows remote attackers to cause a denial of service (CPU consumption) via malformed GIF data that causes an infinite loop.
gd-2.0.15 in Corporate 3.0 is not affected by this issue.
Packages have been patched to correct this issue.
SolutionUpdate the affected packages.