CVE-2007-3473 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 13.3% (pctl 96)
Patch early
A public exploit exists.
Description
The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
| EPSS | 13.31% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-06-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| libgd | gd graphics library |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GD Graphics Library 2.0.34 - 'libgd' gdImageCreateXbm Function Unspecified Denial of Service | 2007-06-26 |
References
- ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz
- http://bugs.libgd.org/?do=details&task_id=94
- http://fedoranews.org/updates/FEDORA-2007-205.shtml
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html
- http://osvdb.org/37744
- http://secunia.com/advisories/25855
- http://secunia.com/advisories/25860
- http://secunia.com/advisories/26272
- http://secunia.com/advisories/26390
- http://secunia.com/advisories/26415
- http://secunia.com/advisories/26467
- http://secunia.com/advisories/26663
- http://secunia.com/advisories/26766
- http://secunia.com/advisories/26856
- http://secunia.com/advisories/29157
- http://secunia.com/advisories/30168
- http://secunia.com/advisories/42813
- http://security.gentoo.org/glsa/glsa-200708-05.xml
- http://security.gentoo.org/glsa/glsa-200711-34.xml
→ the Explorer · watch your stack · NVD