VDB

DEBIAN-CVE-2006-4484

DEBIAN-CVE-2006-4484 PUBLISHED CVSS 9.300000190734863 CRITICAL

Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:12libgd20, 0, 0
Debian:11libgd20, 0, 0
Debian:13xloadimage4.1-26, 0, 4.1-27
Debian:11xloadimage4.1-27, 4.1-26, 0
Debian:13libgd20, 0, 0
Debian:14libgd20, 0, 0
Debian:14xloadimage0, 4.1-27, 4.1-26
Debian:12xloadimage0, 4.1-25, 4.1-26

Timeline

  • Aug 31, 2006 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›