Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 24: 2016-0c57b12c7b Critical Vulnerability: Gd Heap Overflow Alert

fedora
Calendar Grey May 7, 2016
Dist Fedora Esm H88
Update for heap overflow vulnerability in gd library on Fedora 24 related to CVE-2016-3074, essential for securing web apps.
Security fix for CVE-2016-3074

Summary

The gd graphics library allows your code to quickly draw images

complete with lines, arcs, text, multiple colors, cut and paste from

other images, and flood fills, and to write out the result as a PNG or

JPEG file. This is particularly useful in Web applications, where PNG

and JPEG are two of the formats accepted for inline images by most

browsers. Note that gd is not a paint program.

Update Information:

Security fix for CVE-2016-3074

Change Log

References


[ 1 ] Bug #1321893 - CVE-2016-3074 php: Signedness vulnerability causing heap overflow in libgd https://bugzilla.redhat.com/show_bug.cgi?id=1321893

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update gd' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: gd
Product: Fedora 24
Version: 2.1.1
Release: 7.fc24
Summary: A graphics library for quick creation of PNG or JPEG images

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here