CVE Vulnerabilities

CVE-2006-2906

Published: Jun 08, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.4 MEDIUM
AV:N/AC:H/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.0.33 allows remote attackers to cause a denial of service (CPU consumption) via malformed GIF data that causes an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
Graphics_draw_libraryThomas_boutell2.0.33 (including)2.0.33 (including)
Libgd2Ubuntudapper*
Libgd2Ubuntudevel*
Libgd2Ubuntuedgy*
Libgd2Ubuntufeisty*

References