Solution
Please Install the Updated Packages.
Insight
The gd packages provide a graphics library used for the dynamic creation of images, such as PNG and JPEG.
A missing input sanitization flaw, leading to a buffer overflow, was discovered in the gd library. A specially-crafted GD image file could cause an application using the gd library to crash or, possibly, execute arbitrary code when opened. (CVE-2009-3546)
Users of gd should upgrade to these updated packages, which contain a backported patch to resolve this issue.
Affected
gd on CentOS 4
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-3546 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities