{"id":"DEBIAN-CVE-2009-3546","details":"The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.","modified":"2026-09-22T16:47:25.046918986Z","published":"2009-10-19T20:00:00.657Z","upstream":["CVE-2009-3546"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2009-3546"}],"affected":[{"package":{"name":"libgd2","ecosystem":"Debian:12","purl":"pkg:deb/debian/libgd2?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.36~rc1~dfsg-3.1"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3546.json"}},{"package":{"name":"libgd2","ecosystem":"Debian:13","purl":"pkg:deb/debian/libgd2?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.36~rc1~dfsg-3.1"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3546.json"}},{"package":{"name":"libgd2","ecosystem":"Debian:14","purl":"pkg:deb/debian/libgd2?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.36~rc1~dfsg-3.1"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3546.json"}},{"package":{"name":"libwmf","ecosystem":"Debian:12","purl":"pkg:deb/debian/libwmf?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.2.12-5.1","0.2.12-5.2","0.2.13-1","0.2.13-1.1","0.2.13-2","0.2.14-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3546.json"}},{"package":{"name":"libwmf","ecosystem":"Debian:13","purl":"pkg:deb/debian/libwmf?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.2.13-1.1","0.2.13-2","0.2.14-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3546.json"}},{"package":{"name":"libwmf","ecosystem":"Debian:14","purl":"pkg:deb/debian/libwmf?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.2.13-1.1","0.2.13-2","0.2.14-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3546.json"}},{"package":{"name":"racket","ecosystem":"Debian:12","purl":"pkg:deb/debian/racket?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.2-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3546.json"}},{"package":{"name":"racket","ecosystem":"Debian:13","purl":"pkg:deb/debian/racket?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.2-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3546.json"}},{"package":{"name":"racket","ecosystem":"Debian:14","purl":"pkg:deb/debian/racket?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.2-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3546.json"}}],"schema_version":"1.9.0"}