Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 24: 2017-2717b02630 Critical: gd Image Processing DoS Threats

fedora
Calendar Grey January 24, 2017
Dist Fedora Esm H88
Essential revisions for the libpng package in Fedora 25 resolve security vulnerabilities and enhance image handling performance.
## Version 2.2.4 - 2017-01-18 ### Security - gdImageCreate() doesn't check for oversized images and as such is prone to DoS vulnerabilities

Summary

The gd graphics library allows your code to quickly draw images

complete with lines, arcs, text, multiple colors, cut and paste from

other images, and flood fills, and to write out the result as a PNG or

JPEG file. This is particularly useful in Web applications, where PNG

and JPEG are two of the formats accepted for inline images by most

browsers. Note that gd is not a paint program.

Update Information:

## Version 2.2.4 - 2017-01-18 ### Security - gdImageCreate() doesn't check for oversized images and as such is prone to DoS vulnerabilities. (CVE-2016-9317) - double-free in gdImageWebPtr() (CVE-2016-6912) - potential unsigned underflow in gd_interpolation.c - DOS vulnerability in gdImageCreateFromGd2Ctx() ### Fixed - Fix #354: Signed Integer Overflow gd_io.c - Fix #340: System frozen - Fix OOB reads of the TGA decompression buffer - Fix DOS vulnerability in gdImageCreateFromGd2Ctx() - Fix potential unsigned underflow - Fix double-free in gdImageWebPtr() - Fix invalid read in gdImageCreateFromTiffPtr() - Fix OOB reads of the TGA decompression buffer - Fix #68: gif: buffer underflow reported by AddressSanitizer - Avoid potentially dangerous signed to unsigned conversion - Fix #304: test suite failure in gif/bug00006 [2.2.3] - Fix #329: GD_BILINEAR_FIXED gdImageScale() can cause black border - Fix #330: Integer overflow in gdImageScaleBilinearPalette() - Fix 321: Null pointer de...

Change Log

References

Fedora Update Notification FEDORA-2017-2717b02630 2017-01-23 23:54:30.270365
Name : gd Product : Fedora 24 Version : 2.2.4 Release : 1.fc24 URL : https://libgd.github.io/ Summary : A graphics library for quick creation of PNG or JPEG images Description : The gd graphics library allows your code to quickly draw images complete with lines, arcs, text, multiple colors, cut and paste from other images, and flood fills, and to write out the result as a PNG or JPEG file. This is particularly useful in Web applications, where PNG and JPEG are two of the formats accepted for inline images by most browsers. Note that gd is not a paint program.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade gd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: gd
Product: Fedora 24
Version: 2.2.4
Release: 1.fc24
Summary: A graphics library for quick creation of PNG or JPEG images

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here