CVE-2009-3546 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3546): The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.0, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.
Maintainers, please provide a fixed ebuild.
Created attachment 209726 [details] gd-2.0.35.ebuild.patch @mike: any objections to commit these two files?
Created attachment 209727 [details] gd-2.0.35-maxcolors.patch
looks fine to me, thanks
bumped in cvs. *gd-2.0.35-r1 (09 Nov 2009) 09 Nov 2009; Markus Meier <maekke@gentoo.org> +gd-2.0.35-r1.ebuild, +files/gd-2.0.35-maxcolors.patch: revision bump wrt security bug #292130
Arches, please stabilise =media-libs/gd-2.0.35-r1 target keywords: alpha amd64 arm hppa ia64 m68k ~mips ppc ppc64 s390 sh sparc ~sparc-fbsd x86 ~x86-fbsd
x86 stable
amd64 stable
alpha/arm/ia64/m68k/s390/sh/sparc stable
Stable for HPPA.
ppc64 done
ppc stable
GLSA request filed.
GLSA 201006-16