Unrated severityNVD Advisory· Published Mar 1, 2005· Updated Apr 16, 2026
CVE-2004-0990
CVE-2004-0990
Description
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.
Affected products
25cpe:2.3:a:gd_graphics_library:gdlib:1.8.4:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:gd_graphics_library:gdlib:1.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:gd_graphics_library:gdlib:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:gd_graphics_library:gdlib:2.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:gd_graphics_library:gdlib:2.0.20:*:*:*:*:*:*:*
- cpe:2.3:a:gd_graphics_library:gdlib:2.0.21:*:*:*:*:*:*:*
- cpe:2.3:a:gd_graphics_library:gdlib:2.0.22:*:*:*:*:*:*:*
- cpe:2.3:a:gd_graphics_library:gdlib:2.0.23:*:*:*:*:*:*:*
- cpe:2.3:a:gd_graphics_library:gdlib:2.0.26:*:*:*:*:*:*:*
- cpe:2.3:a:gd_graphics_library:gdlib:2.0.27:*:*:*:*:*:*:*
- cpe:2.3:a:gd_graphics_library:gdlib:2.0.28:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:8.1:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.0:*:x86_64:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.1:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.2:*:*:*:*:*:*:*
cpe:2.3:o:trustix:secure_linux:1.5:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:trustix:secure_linux:1.5:*:*:*:*:*:*:*
- cpe:2.3:o:trustix:secure_linux:2.0:*:*:*:*:*:*:*
- cpe:2.3:o:trustix:secure_linux:2.1:*:*:*:*:*:*:*
- cpe:2.3:o:trustix:secure_linux:2.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
26- www.securityfocus.com/bid/11523nvdPatchVendor Advisory
- lists.suse.com/archive/suse-security-announce/2006-Feb/0001.htmlnvd
- marc.infonvd
- secunia.com/advisories/18717nvd
- secunia.com/advisories/20824nvd
- secunia.com/advisories/20866nvd
- secunia.com/advisories/21050nvd
- secunia.com/advisories/23783nvd
- www.ciac.org/ciac/bulletins/p-071.shtmlnvd
- www.debian.org/security/2004/dsa-589nvd
- www.debian.org/security/2004/dsa-591nvd
- www.debian.org/security/2004/dsa-601nvd
- www.debian.org/security/2004/dsa-602nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.osvdb.org/11190nvd
- www.redhat.com/support/errata/RHSA-2004-638.htmlnvd
- www.trustix.org/errata/2004/0058nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17866nvd
- issues.rpath.com/browse/RPL-939nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1260nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9952nvd
- www.ubuntu.com/usn/usn-11-1/nvd
- www.ubuntu.com/usn/usn-25-1/nvd
News mentions
0No linked articles in our index yet.