VYPR
Unrated severityNVD Advisory· Published Mar 1, 2005· Updated Apr 16, 2026

CVE-2004-0990

CVE-2004-0990

Description

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

Affected products

25
  • cpe:2.3:a:gd_graphics_library:gdlib:1.8.4:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:gd_graphics_library:gdlib:1.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gd_graphics_library:gdlib:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gd_graphics_library:gdlib:2.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:gd_graphics_library:gdlib:2.0.20:*:*:*:*:*:*:*
    • cpe:2.3:a:gd_graphics_library:gdlib:2.0.21:*:*:*:*:*:*:*
    • cpe:2.3:a:gd_graphics_library:gdlib:2.0.22:*:*:*:*:*:*:*
    • cpe:2.3:a:gd_graphics_library:gdlib:2.0.23:*:*:*:*:*:*:*
    • cpe:2.3:a:gd_graphics_library:gdlib:2.0.26:*:*:*:*:*:*:*
    • cpe:2.3:a:gd_graphics_library:gdlib:2.0.27:*:*:*:*:*:*:*
    • cpe:2.3:a:gd_graphics_library:gdlib:2.0.28:*:*:*:*:*:*:*
  • OpenPKG/Openpkg3 versions
    cpe:2.3:a:openpkg:openpkg:2.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:openpkg:openpkg:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:openpkg:openpkg:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:openpkg:openpkg:current:*:*:*:*:*:*:*
  • cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*
  • SUSE S.A./Linux7 versions
    cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:8.1:*:*:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:8.2:*:*:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:9.0:*:*:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:9.0:*:x86_64:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:9.1:*:*:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:9.2:*:*:*:*:*:*:*
  • cpe:2.3:o:trustix:secure_linux:1.5:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:trustix:secure_linux:1.5:*:*:*:*:*:*:*
    • cpe:2.3:o:trustix:secure_linux:2.0:*:*:*:*:*:*:*
    • cpe:2.3:o:trustix:secure_linux:2.1:*:*:*:*:*:*:*
    • cpe:2.3:o:trustix:secure_linux:2.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

26

News mentions

0

No linked articles in our index yet.