Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 538
Alerts This Week
Warning Icon 1 538

Ubuntu 16.04 LTS USN-3030-1 Critical: libgd Denial Of Service

ubuntu
Calendar Grey July 11, 2016
Scroller Ubuntu
Multiple vulnerabilities in libgd identified across different Ubuntu distributions may result in application crashes or facilitate unauthorized code execution.
The GD library could be made to crash or run programs if it processed a specially crafted image file.

Summary

The GD library could be made to crash or run programs if it processed a

specially crafted image file.

Software Description:

- libgd2: GD Graphics Library

Details:

It was discovered that the GD library incorrectly handled memory when using

gdImageScaleTwoPass(). A remote attacker could possibly use this issue to

cause a denial of service. This issue only affected Ubuntu 14.04 LTS.

(CVE-2013-7456)

It was discovered that the GD library incorrectly handled certain malformed

XBM images. If a user or automated system were tricked into processing a

specially crafted XBM image, an attacker could cause a denial of service.

This issue only affected Ubuntu 14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04

LTS. (CVE-2016-5116)

It was discovered that the GD library incorrectly handled memory when using

_gd2GetHeader(). A remote attacker could possibly use this issue to cause a

denial of service or possibly execute arbitrary code. (CVE-2016-5766)

It was discovered that the G...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  libgd3                          2.1.1-4ubuntu0.16.04.2

Ubuntu 15.10:
  libgd3                          2.1.1-4ubuntu0.15.10.2

Ubuntu 14.04 LTS:
  libgd3                          2.1.0-3ubuntu0.2

Ubuntu 12.04 LTS:
  libgd2-noxpm                    2.0.36~rc1~dfsg-6ubuntu2.2
  libgd2-xpm                      2.0.36~rc1~dfsg-6ubuntu2.2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3030-1

CVE-2013-7456, CVE-2016-5116, CVE-2016-5766, CVE-2016-6128,

CVE-2016-6161

Severity
critical
Lowest
Low
Medium
High
Critical

July 11, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.