← Vulnerability feed

Vulnerability record · CVE-2007-3477 · published 28 June 2007

CVE-2007-3477: Libgd gd graphics library vulnerability

Libgd · Gd Graphics Library

The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value.

5.0 CVSS 2.0 Medium EPSS 4.9% · top 8.3% CWE-399 · CWE-399
5.0CVSS 2.0 base score
4.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
66References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz Patch
http://bugs.libgd.org/?do=details&task_id=74 Exploit
http://bugs.libgd.org/?do=details&task_id=92
http://fedoranews.org/updates/FEDORA-2007-205.shtml
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html
http://osvdb.org/42062
http://secunia.com/advisories/25860 Vendor Advisory
http://secunia.com/advisories/26272 Vendor Advisory
http://secunia.com/advisories/26390 Vendor Advisory
http://secunia.com/advisories/26415 Vendor Advisory
http://secunia.com/advisories/26467 Vendor Advisory
http://secunia.com/advisories/26663 Vendor Advisory
http://secunia.com/advisories/26766 Vendor Advisory
http://secunia.com/advisories/26856 Vendor Advisory
http://secunia.com/advisories/30168 Vendor Advisory
http://secunia.com/advisories/31168 Vendor Advisory
http://secunia.com/advisories/42813 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200708-05.xml
http://security.gentoo.org/glsa/glsa-200711-34.xml
http://security.gentoo.org/glsa/glsa-200805-13.xml
http://www.debian.org/security/2008/dsa-1613
http://www.libgd.org/ReleaseNote020035 Patch
http://www.mandriva.com/security/advisories?name=MDKSA-2007:153
http://www.mandriva.com/security/advisories?name=MDKSA-2007:164
http://www.novell.com/linux/security/advisories/2007_15_sr.html
http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00311.html
http://www.securityfocus.com/archive/1/478796/100/0/threaded
http://www.securityfocus.com/bid/24651
http://www.trustix.org/errata/2007/0024/
http://www.vupen.com/english/advisories/2011/0022 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=277421
https://issues.rpath.com/browse/RPL-1643
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/gd-2.0.35-i486-1_slack11.0.tgz Patch
http://bugs.libgd.org/?do=details&task_id=74 Exploit
http://bugs.libgd.org/?do=details&task_id=92
http://fedoranews.org/updates/FEDORA-2007-205.shtml
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html
http://osvdb.org/42062

Track CVE-2007-3477 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-3546Libgd gd graphics library memory buffer overflow vulnerabilityThe _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colors…EPSS 10%4.3CVE-2007-3472Libgd gd graphics library vulnerabilityInteger overflow in gdImageCreateTrueColor function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to have un…EPSS 7.3%4.3CVE-2007-3473Libgd gd graphics library vulnerabilityThe gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (cr…EPSS 13%2.6CVE-2007-3474Libgd gd graphics library vulnerabilityMultiple unspecified vulnerabilities in the GIF reader in the GD Graphics Library (libgd) before 2.0.35 have unspecified impact and user-assisted rem…EPSS 2.5%8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed5.9CVE-2018-0180Cisco IOS Login Block feature denial-of-service via crafted login attemptsMultiple flaws in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated remote attacker trigger a reload of the d…KEVEPSS 4.9%analysed5.9CVE-2018-0179Cisco IOS Login Block feature denial-of-service flawMultiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated, remote attacker trigger a relo…KEVEPSS 4.9%analysed6.3CVE-2018-0161Cisco IOS SNMP GET Request Causes Device RestartCisco IOS Software on certain Catalyst switches mishandles SNMP read requests for the ciscoFlashMIB object ID, causing a SYS-3-CPUHOG condition that …KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2007-3477), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.