Dit bericht is nog niet vertaald

[USN-557-1] GD library vulnerability

Ubuntu Security Notice USN-557-1          December 18, 2007
libgd2 vulnerability
CVE-2007-3996
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
libgd2-noxpm 2.0.33-2ubuntu5.3
libgd2-xpm 2.0.33-2ubuntu5.3
Ubuntu 6.10
libgd2-noxpm 2.0.33-4ubuntu2.2
libgd2-xpm 2.0.33-4ubuntu2.2
Ubuntu 7.10
libgd2-noxpm 2.0.34-1ubuntu1.1
libgd2-xpm 2.0.34-1ubuntu1.1
Ubuntu 7.04
libgd2-noxpm 2.0.34~rc1-2ubuntu1.2
libgd2-xpm 2.0.34~rc1-2ubuntu1.2

In general, a standard system upgrade is sufficient to effect the necessary changes.

Mattias Bengtsson and Philip Olausson discovered that the GD library did not properly perform bounds checking when creating images. An attacker could send specially crafted input to applications linked against libgd2 and cause a denial of service or possibly execute arbitrary code.