The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.
CVSS Details
- CVSS 3.1 Base Score: 3.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 18, 2007 |
| Debian | — | Upgrade libgd2 | Jul 30, 2024 | May 18, 2007 |
| Freebsd | — | Upgrade libwmf | Dec 10, 2025 | Jul 15, 2015 |
| Gentoo Linux | — | Upgrade media-libs/gd.Upgrade dev-lang/php. | Oct 30, 2017 | May 18, 2007 |
| Oracle_linux | — | Upgrade php-ncursesUpgrade phpUpgrade php-ldapUpgrade gdUpgrade gd-progsUpgrade php-soapUpgrade php-bcmathUpgrade php-cliUpgrade php-xmlUpgrade php-imapUpgrade php-snmpUpgrade php-dbaUpgrade php-gdUpgrade gd-develUpgrade php-pdoUpgrade php-commonUpgrade php-odbcUpgrade php-xmlrpcUpgrade php-develUpgrade php-mysqlUpgrade php-mbstringUpgrade php-pgsql | Oct 16, 2024 | May 18, 2007 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 16, 2007 |
| Suse | — | Upgrade gdUpgrade libgd3Upgrade gd-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgd2-xpmUpgrade libgd2-noxpm | Nov 8, 2024 | May 18, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub