![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.57049 |
Category: | Ubuntu Local Security Checks |
Title: | Ubuntu USN-298-1 (libgd2) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to libgd2 announced via advisory USN-298-1. A security issue affects the following Ubuntu releases: Ubuntu 5.04 Ubuntu 5.10 Ubuntu 6.06 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. Xavier Roche discovered that libgd's function for reading GIF image data did not sufficiently verify its validity. Specially crafted GIF images could cause an infinite loop which used up all available CPU resources. Since libgd is often used in PHP and Perl web applications, this could lead to a remote Denial of Service vulnerability. Solution: The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.04: libgd2-noxpm 2.0.33-1.1ubuntu1.5.04 libgd2-xpm 2.0.33-1.1ubuntu1.5.04 Ubuntu 5.10: libgd2-noxpm 2.0.33-1.1ubuntu1.5.10 libgd2-xpm 2.0.33-1.1ubuntu1.5.10 Ubuntu 6.06 LTS: libgd2-noxpm 2.0.33-2ubuntu5.1 libgd2-xpm 2.0.33-2ubuntu5.1 After a standard system upgrade you need to reboot your computer to effect the necessary changes. https://secure1.securityspace.com/smysecure/catid.html?in=USN-298-1 Risk factor : High CVSS Score: 5.4 |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-2906 BugTraq ID: 18294 http://www.securityfocus.com/bid/18294 Bugtraq: 20060606 libgd 2.0.33 infinite loop in GIF decoding ? (Google Search) http://www.securityfocus.com/archive/1/436132 Debian Security Information: DSA-1117 (Google Search) http://www.debian.org/security/2006/dsa-1117 http://www.mandriva.com/security/advisories?name=MDKSA-2006:112 http://www.mandriva.com/security/advisories?name=MDKSA-2006:113 http://www.mandriva.com/security/advisories?name=MDKSA-2006:122 http://secunia.com/advisories/20500 http://secunia.com/advisories/20571 http://secunia.com/advisories/20676 http://secunia.com/advisories/20853 http://secunia.com/advisories/20866 http://secunia.com/advisories/20887 http://secunia.com/advisories/21050 http://secunia.com/advisories/21186 http://secunia.com/advisories/23783 http://securityreason.com/securityalert/1067 SuSE Security Announcement: SUSE-SA:2006:031 (Google Search) http://www.novell.com/linux/security/advisories/2006_31_php.html http://www.trustix.org/errata/2006/0038 https://usn.ubuntu.com/298-1/ http://www.vupen.com/english/advisories/2006/2174 XForce ISS Database: gdgraphicslibrary-gif-dos(26976) https://exchange.xforce.ibmcloud.com/vulnerabilities/26976 |
Copyright | Copyright (c) 2006 E-Soft Inc. http://www.securityspace.com |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |