NewStart CGSL MAIN 6.06 : gd Multiple Vulnerabilities (NS-SA-2026-0053)

critical Nessus Plugin ID 330497

Synopsis

The remote NewStart CGSL host is affected by multiple vulnerabilities.

Description

The remote NewStart CGSL host, running version MAIN 6.06, has gd packages installed that are affected by multiple vulnerabilities:

- The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected. (CVE-2019-6978)

- The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information. (CVE-2009-3546)

- Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font. (CVE-2007-0455)

- The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file. (CVE-2014-2497)

- Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow. (CVE-2016-3074)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the vulnerable CGSL gd packages. Note that updated packages may not be available yet. Please contact ZTE for more information.

See Also

https://security.gd-linux.com/info/CVE-2007-0455

https://security.gd-linux.com/info/CVE-2009-3546

https://security.gd-linux.com/info/CVE-2014-2497

https://security.gd-linux.com/info/CVE-2016-3074

https://security.gd-linux.com/info/CVE-2016-6911

https://security.gd-linux.com/info/CVE-2016-7568

https://security.gd-linux.com/info/CVE-2016-8670

https://security.gd-linux.com/info/CVE-2017-6362

https://security.gd-linux.com/info/CVE-2017-7890

https://security.gd-linux.com/info/CVE-2018-1000222

https://security.gd-linux.com/info/CVE-2018-14553

https://security.gd-linux.com/info/CVE-2018-5711

https://security.gd-linux.com/info/CVE-2019-6977

https://security.gd-linux.com/info/CVE-2019-6978

https://security.gd-linux.com/info/CVE-2021-40145

https://security.gd-linux.com/notice/NS-SA-2026-0053

Plugin Details

Severity: Critical

ID: 330497

File Name: newstart_cgsl_NS-SA-2026-0053_gd.nasl

Version: 1.1

Type: Local

Published: 7/29/2026

Updated: 7/29/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2009-3546

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2019-6978

Vulnerability Information

CPE: cpe:/o:zte:cgsl_main:6, p-cpe:/a:zte:cgsl_main:gd

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/ZTE-CGSL/release, Host/ZTE-CGSL/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/27/2026

Vulnerability Publication Date: 1/29/2007

Reference Information

CVE: CVE-2007-0455, CVE-2009-3546, CVE-2014-2497, CVE-2016-3074, CVE-2016-6911, CVE-2016-7568, CVE-2016-8670, CVE-2017-6362, CVE-2017-7890, CVE-2018-1000222, CVE-2018-14553, CVE-2018-5711, CVE-2019-6977, CVE-2019-6978, CVE-2021-40145