Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 439
Alerts This Week
Warning Icon 1 439

Mageia: 2020-0098 Moderate: libgd NULL Pointer Crash Risk

mageia
Calendar Grey February 24, 2020
Scroller Mageia
Mageia has responded to important libgd security weaknesses that may cause application failures. Investigate available patches and further information.
The updated packages fix a security vulnerability: gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application ...

Summary

The updated packages fix a security vulnerability:
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. (CVE-2018-14553)

References

- https://bugs.mageia.org/show_bug.cgi?id=26220

- https://lists.debian.org/debian-lts-announce/2020/02/msg00014.html

- https://www.cve.org/CVERecord?id=CVE-2018-14553

Resolution

SRPMS

- 7/core/libgd-2.2.5-5.1.mga7

Publication date: 24 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0098.html
Type: security
CVE: CVE-2018-14553

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.