CVE

CVE-2007-3478

Severity:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
28/06/2007
Last modified:
16/10/2018

Description

Race condition in gdImageStringFTEx (gdft_draw_bitmap) in gdft.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors, possibly involving truetype font (TTF) support.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gd_graphics_library:gdlib:*:*:*:*:*:*:*:* 2.0.34 (including)