漏洞信息详情
GD图形库多个未指定的远程缓冲区溢出漏洞
- CNNVD编号:CNNVD-200502-023
- 危害等级: 超危
- CVE编号:
CVE-2004-0941
- 漏洞类型:
缓冲区溢出
- 发布时间:
2005-02-09
- 威胁类型:
远程
- 更新时间:
2005-10-28
- 厂 商:
trustix - 漏洞来源:
The individual or … -
漏洞简介
libGD(又名GD Graphics Library或libgd2)是美国软件开发者Thomas Boutell所研发的一个开源的用于动态创建图像的库,它支持创建图表、图形和缩略图等。
gd图形库(libgd) 2.0.21及更早版本中的多个缓冲区溢出,可让远程攻击者通过形态异常的图像文件执行任意代码(这些图像文件会因错误调用gdMalloc函数而触发溢出),它是一组与CVE-2004-0990不同的漏洞。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
wvWare libwmf 0.2.8
Mandriva lib64wmf0.2_7-0.2.8-6.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva lib64wmf0.2_7-devel-0.2.8-6.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva libwmf-0.2.8-6.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva libwmf-0.2.8-6.1.C30mdk.src.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva libwmf-0.2.8-6.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva libwmf0.2_7-0.2.8-6.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
Mandriva libwmf0.2_7-devel-0.2.8-6.1.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
GD Graphics Library gdlib 1.8.4
Debian libgd-dev_1.8.4-17.woody4_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_alpha.deb
Debian libgd-dev_1.8.4-17.woody4_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_arm.deb
Debian libgd-dev_1.8.4-17.woody4_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_hppa.deb
Debian libgd-dev_1.8.4-17.woody4_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_i386.deb
Debian libgd-dev_1.8.4-17.woody4_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_ia64.deb
Debian libgd-dev_1.8.4-17.woody4_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_m68k.deb
Debian libgd-dev_1.8.4-17.woody4_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_mips.deb
Debian libgd-dev_1.8.4-17.woody4_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_mipsel.deb
Debian libgd-dev_1.8.4-17.woody4_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_powerpc.deb
Debian libgd-dev_1.8.4-17.woody4_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_s390.deb
Debian libgd-dev_1.8.4-17.woody4_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_sparc.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_alpha.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_arm.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_hppa.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_i386.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_ia64.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_m68k.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_mips.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_mipsel.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_powerpc.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_s390.deb
Debian libgd-noxpm-dev_1.8.4-17.woody4_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_sparc.deb
Debian libgd1-noxpm_1.8.4-17.woody4_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_arm.deb
Debian libgd1-noxpm_1.8.4-17.woody4_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_hppa.deb
Debian libgd1-noxpm_1.8.4-17.woody4_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_i386.deb
Debian libgd1-noxpm_1.8.4-17.woody4_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_ia64.deb
Debian libgd1-noxpm_1.8.4-17.woody4_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_m68k.deb
Debian libgd1-noxpm_1.8.4-17.woody4_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_mips.deb
Debian libgd1-noxpm_1.8.4-17.woody4_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_mipsel.deb
Debian libgd1-noxpm_1.8.4-17.woody4_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_powerpc.deb
参考网址
来源: TRUSTIX
名称: 2004-0058
链接:http://www.trustix.org/errata/2004/0058
来源: BID
名称: 11663
链接:http://www.securityfocus.com/bid/11663
来源: SECUNIA
名称: 13179
链接:http://secunia.com/advisories/13179/
来源: UBUNTU
名称: USN-25-1
链接:http://seclists.org/lists/bugtraq/2004/Nov/0203.html
来源: XF
名称: gd-graphics-gdmalloc-bo(18048)
链接:http://xforce.iss.net/xforce/xfdb/18048
来源: UBUNTU
名称: USN-33-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-33-1
来源: REDHAT
名称: RHSA-2006:0194
链接:http://www.redhat.com/support/errata/RHSA-2006-0194.html
来源: REDHAT
名称: RHSA-2004:638
链接:http://www.redhat.com/support/errata/RHSA-2004-638.html
来源: MANDRIVA
名称: MDKSA-2006:122
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:122
来源: MANDRIVA
名称: MDKSA-2006:114
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:114
来源: MANDRIVA
名称: MDKSA-2006:113
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:113
来源: DEBIAN
名称: DSA-601
链接:http://www.debian.org/security/2004/dsa-601
来源: CIAC
名称: P-071
链接:http://www.ciac.org/ciac/bulletins/p-071.shtml
来源: SECUNIA
名称: 21050
链接:http://secunia.com/advisories/21050
来源: SECUNIA
名称: 20824
链接:http://secunia.com/advisories/20824
来源: SECUNIA
名称: 18686
链接:http://secunia.com/advisories/18686
来源: MANDRIVA
名称: MDKSA-2006:122
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122
来源: MANDRIVA
名称: MDKSA-2006:114
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:114
来源: MANDRIVA
名称: MDKSA-2006:113
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:113
来源: US Government Resource: oval:org.mitre.oval:def:1195
名称: oval:org.mitre.oval:def:1195
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1195