CVE-2006-4484

Publication date 31 August 2006

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.

Status

Package Ubuntu Release Status
php5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 5.1.2-1ubuntu3.9

References

Related Ubuntu Security Notices (USN)

    • USN-342-1
    • PHP vulnerabilities
    • 7 September 2006

Other references