The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected. (CVE-2019-6978) References: . MGASA-2019-0085 - Updated libwmf packages fix security vulnerability Publication date: 14 Feb 2019 URL: https://advisories.mageia.org/MGASA-2019-0085.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-6978 The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected. (CVE-2019-6978) References: - https://bugs.mageia.org/show_bug.cgi?id=24344 - https://lists.fedoraproject.org/archives/list/
The updated packages fix security vulnerabilities: gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a . MGASA-2018-0367 - Updated libgd packages fix security vulnerabilities Publication date: 02 Sep 2018 URL: https://advisories.mageia.org/MGASA-2018-0367.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-5711, CVE-2018-1000222 The updated packages fix security vulnerabilities: gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx (CVE-2018-5711). Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free (CVE-2018-1000222). References: - https://bugs.mageia.org/show_bug.cgi?id=23496 - https://ubuntu.com/security/notices/USN-3755-1 - https://www.cve.org/CVERecord?id=CVE-2018-5711 - https://www.cve.org/CVERecord?id=CVE-2018-1000222 SRPMS: - 6/core/libgd-2.2.5-2.1.mga6 . Revised libgd versions address significant security flaws, notably infinite looping and remote execution vulnerabilities within Mageia.. Mageia Security Update, libgd Vulnerability Fix, PHP Security Patch, Remote Code Execution, GD Library Exploit. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.