{"id":"DEBIAN-CVE-2006-4484","details":"Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.","modified":"2026-09-17T06:47:34.716773265Z","published":"2006-08-31T21:04:00Z","upstream":["CVE-2006-4484"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2006-4484"}],"affected":[{"package":{"name":"libgd2","ecosystem":"Debian:12","purl":"pkg:deb/debian/libgd2?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.33-5.1"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2006-4484.json"}},{"package":{"name":"libgd2","ecosystem":"Debian:13","purl":"pkg:deb/debian/libgd2?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.33-5.1"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2006-4484.json"}},{"package":{"name":"libgd2","ecosystem":"Debian:14","purl":"pkg:deb/debian/libgd2?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.33-5.1"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2006-4484.json"}},{"package":{"name":"xloadimage","ecosystem":"Debian:12","purl":"pkg:deb/debian/xloadimage?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.1-25","4.1-26","4.1-27"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2006-4484.json"}},{"package":{"name":"xloadimage","ecosystem":"Debian:13","purl":"pkg:deb/debian/xloadimage?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.1-26","4.1-27"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2006-4484.json"}},{"package":{"name":"xloadimage","ecosystem":"Debian:14","purl":"pkg:deb/debian/xloadimage?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.1-26","4.1-27"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2006-4484.json"}}],"schema_version":"1.9.0"}