The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.
CVSS Details
- CVSS 3.1 Base Score: 3.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 18, 2007 |
| Debian | — | Upgrade libgd2 | Jul 30, 2024 | May 18, 2007 |
| Freebsd | — | Upgrade libwmf | Dec 10, 2025 | Jul 15, 2015 |
| Gentoo Linux | — | Upgrade dev-lang/php.Upgrade media-libs/gd. | Oct 30, 2017 | May 18, 2007 |
| Oracle_linux | — | Upgrade php-ldapUpgrade php-ncursesUpgrade php-snmpUpgrade php-dbaUpgrade php-pdoUpgrade php-cliUpgrade phpUpgrade php-bcmathUpgrade php-gdUpgrade gd-develUpgrade gdUpgrade php-xmlUpgrade php-soapUpgrade gd-progsUpgrade php-imapUpgrade php-pgsqlUpgrade php-commonUpgrade php-mysqlUpgrade php-xmlrpcUpgrade php-odbcUpgrade php-mbstringUpgrade php-devel | Oct 16, 2024 | May 18, 2007 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 16, 2007 |
| Suse | — | Upgrade libgd3Upgrade gd-develUpgrade gd | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgd2-noxpmUpgrade libgd2-xpm | Nov 8, 2024 | May 18, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub