Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Ubuntu 16.04 LTS USN-3030-1 Critical: libgd Denial Of Service

Ubuntu Large Esm H500
The GD library could be made to crash or run programs if it processed a specially crafted image file.
=========================================================================Ubuntu Security Notice USN-3030-1
July 11, 2016

libgd2 vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

The GD library could be made to crash or run programs if it processed a
specially crafted image file.

Software Description:
- libgd2: GD Graphics Library

Details:

It was discovered that the GD library incorrectly handled memory when using
gdImageScaleTwoPass(). A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2013-7456)

It was discovered that the GD library incorrectly handled certain malformed
XBM images. If a user or automated system were tricked into processing a
specially crafted XBM image, an attacker could cause a denial of service.
This issue only affected Ubuntu 14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04
LTS. (CVE-2016-5116)

It was discovered that the GD library incorrectly handled memory when using
_gd2GetHeader(). A remote attacker could possibly use this issue to cause a
denial of service or possibly execute arbitrary code. (CVE-2016-5766)

It was discovered that the GD library incorrectly handled certain color
indexes. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 15.10 and
Ubuntu 16.04 LTS. (CVE-2016-6128)

It was discovered that the GD library incorrectly handled memory when
encoding a GIF image. A remote attacker could possibly use this issue to
cause a denial of service. (CVE-2016-6161)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  libgd3                          2.1.1-4ubuntu0.16.04.2

Ubuntu 15.10:
  libgd3                          2.1.1-4ubuntu0.15.10.2

Ubuntu 14.04 LTS:
  libgd3                          2.1.0-3ubuntu0.2

Ubuntu 12.04 LTS:
  libgd2-noxpm                    2.0.36~rc1~dfsg-6ubuntu2.2
  libgd2-xpm                      2.0.36~rc1~dfsg-6ubuntu2.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3030-1
  CVE-2013-7456, CVE-2016-5116, CVE-2016-5766, CVE-2016-6128,
  CVE-2016-6161

Package Information:
  https://launchpad.net/ubuntu/+source/libgd2/2.1.1-4ubuntu0.16.04.2
  https://launchpad.net/ubuntu/+source/libgd2/2.1.1-4ubuntu0.15.10.2
  https://launchpad.net/ubuntu/+source/libgd2/2.1.0-3ubuntu0.2
  https://launchpad.net/ubuntu/+source/libgd2/2.0.36~rc1~dfsg-6ubuntu2.2


Ubuntu 16.04 LTS USN-3030-1 Critical: libgd Denial Of Service

ubuntu
Calendar Grey July 11, 2016
Dist Ubuntu Esm H88
Multiple vulnerabilities in libgd identified across different Ubuntu distributions may result in application crashes or facilitate unauthorized code execution.
The GD library could be made to crash or run programs if it processed a specially crafted image file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libgd3 2.1.1-4ubuntu0.16.04.2 Ubuntu 15.10: libgd3 2.1.1-4ubuntu0.15.10.2 Ubuntu 14.04 LTS: libgd3 2.1.0-3ubuntu0.2 Ubuntu 12.04 LTS: libgd2-noxpm 2.0.36~rc1~dfsg-6ubuntu2.2 libgd2-xpm 2.0.36~rc1~dfsg-6ubuntu2.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3030-1

CVE-2013-7456, CVE-2016-5116, CVE-2016-5766, CVE-2016-6128,

CVE-2016-6161

Severity
critical
Lowest
Low
Medium
High
Critical

July 11, 2016

Package Information

https://launchpad.net/ubuntu/+source/libgd2/2.1.1-4ubuntu0.16.04.2 https://launchpad.net/ubuntu/+source/libgd2/2.1.1-4ubuntu0.15.10.2 https://launchpad.net/ubuntu/+source/libgd2/2.1.0-3ubuntu0.2 https://launchpad.net/ubuntu/+source/libgd2/2.0.36~rc1~dfsg-6ubuntu2.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here