Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GD图形库PNG文件处理拒绝服务漏洞
Vulnerability Description
GD是一个开源的代码库,用于为站点动态创建图形。 GD图形库在处理畸形的PNG图形时存在漏洞,远程攻击者可能利用此漏洞导致相关的应用进入死循环。 GD库的libpng解码器的libpng代码(png_read_data())与libgd回调(gdPngReadData())之间没有正确地检测截短的输入,导致死循环,libpng的png_read_info()函数无法返回,函数库会消耗100%的CPU资源。 /* id: gdbad3.c, Xavier Roche, May. 2007 */ /* gcc
CVSS Information
N/A
Vulnerability Type
N/A