GD Graphics Library could be made to crash if it opened a specially crafted file.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ========================================================================== Ubuntu Security Notice USN-7112-1 November 15, 2024 libgd2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - - Ubuntu 22.04 LTS - - Ubuntu 20.04 LTS - - Ubuntu 18.04 LTS - - Ubuntu 16.04 LTS Summary: GD Graphics Library could be made to crash if it opened a specially crafted file. Software Description: - - libgd2: GD Graphics Library Details: It was discovered that the GD Graphics Library did not perform proper bounds checking while handling BMP and WebP files. If a user were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service (application crash). Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libgd-dev 2.3.0-2ubuntu2.3 libgd-tools 2.3.0-2ubuntu2.3 libgd3 2.3.0-2ubuntu2.3 Ubuntu 20.04 LTS libgd-dev 2.2.5-5.2ubuntu2.4 libgd-tools 2.2.5-5.2ubuntu2.4 libgd3 2.2.5-5.2ubuntu2.4 Ubuntu 18.04 LTS libgd-dev 2.2.5-4ubuntu0.5+esm3 Available with Ubuntu Pro libgd-tools 2.2.5-4ubuntu0.5+esm3 Available with Ubuntu Pro libgd3 2.2.5-4ubuntu0.5+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS libgd-dev 2.1.1-4ubuntu0.16.04.12+esm4 Available with Ubuntu Pro libgd-tools 2.1.1-4ubuntu0.16.04.12+esm4 Available with Ubuntu Pro libgd3 2.1.1-4ubuntu0.16.04.12+esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7112-1 CVE-2021-40812 Package Information: https://launchpad.net/ubuntu/+source/libgd2/2.3.0-2ubuntu2.3 https://launchpad.net/ubuntu/+source/libgd2/2.2.5-5.2ubuntu2.4 -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKl1CaPno2Qy4/AU8lFzKVeTWQe4FAmc2q8gACgkQlFzKVeTW Qe5TEw/8D7vt83fOu551WA61LxJDVejpdMvP84dKC5SbgngZ8C71FRjaiL2RNhXM z1r4kU3MYQ64WYcjioCInZVljdxLgwTyPbJ08qIhmupCsPXv/w6Bo1DW6oJn9Pgh 2XGA9wGqFpGnqpUYbJHViSMr9c09TgBpDxTmMUH+iJmxKfYyGC85wD+E9Gta7bT/ jHllFz4hnBCZNDHpDyEB5g9utSszlc2+IkrzOe6Ln1kZbsBYpMU0ww8aoFQZM/lM /hQn43EYxf19yJxgI1QF/eI7ZVcUDrbdTbuxQXe9z8q3qqaybEl3X64N5zknYAII +fE0DO3WBDhEu5jDFXh38jX3GIO6qBMQH6WqhTsJmgpAGD6lJSKT3RxoXF23eDpB CPXUqojiL8s2bEW5jnZ3iBw47gkWGKnS235XEvNMoSJV+s6ka3qYkbdjvL4AN8Hb 42SJM4O+UKMmSiA3ouR3TIrc9MyZ0t+hdzrb6PaDpnCvKcY+O8+sCK0ksmJqmYvp WqZ+HyzFZbbM8t8JT+U5M6LZRWvkv2jGsMg+MPL1ZFeil0m0b6sPhSQp0tbvtGFO YSxQ/sVKB8aVFjZ3MajxQOtIbTJ3TEgOfjAi8S1nvVQHKO1Me+26X5P7KYsJHJKi sUPLU8FqoSmlGK3m6pMM6Y3H9hSYpFoxKu/N8vZpksjXO1hYokc= =TfRa -----END PGP SIGNATURE----- . The GD Graphics Library has released a security advisory noting vulnerabilities that may cause crashes from crafted files. Users should update quickly for protection. libgd2, denial of service, Ubuntu graphics, crash issues. . LinuxSecurity.com Team
It was discovered that there was a potential out-of-bounds write vulnerability in pixman, a pixel-manipulation library used in many Linux graphical applications. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3179-1
The updated packages fix a security vulnerability: The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBuf return value checks (CVE-2021-40812). . MGASA-2021-0449 - Updated libgd packages fix security vulnerability Publication date: 29 Sep 2021 URL: https://advisories.mageia.org/MGASA-2021-0449.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-40812 The updated packages fix a security vulnerability: The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBuf return value checks (CVE-2021-40812). References: - https://bugs.mageia.org/show_bug.cgi?id=29486 - - https://www.cve.org/CVERecord?id=CVE-2021-40812 SRPMS: - 8/core/libgd-2.3.1-1.3.mga8 . Revised libgd components resolve a significant out-of-bounds read vulnerability within Mageia's GD Graphics Library to bolster protection.. Mageia Security Updates, LibGD Vulnerability Fixes, Graphics Library Patches. . LinuxSecurity.com Team
New upstream version 10.94.00. Introduced new script pamhomography.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f62099fe51 2021-02-04 01:56:45.207227 --------------------------------------------------------------------------------Name : netpbm Product : Fedora 32 Version : 10.93.00 Release : 1.fc32 URL : Summary : A library for handling different graphics file formats Description : The netpbm package contains a library of functions which support programs for handling various graphics file formats, including .pbm (portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable pixmaps) and others. --------------------------------------------------------------------------------Update Information: New upstream version 10.94.00. Introduced new script pamhomography. --------------------------------------------------------------------------------ChangeLog: * Mon Jan 25 2021 Josef Ridky - 10.93.00-1 - New upstream release 10.93.00 (#1911159) --------------------------------------------------------------------------------References: [ 1 ] Bug #1561207 - CVE-2018-8975 netpbm: heap-buffer-overflow in pm_mallocarray2 function in lib/util/mallocvar.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1561207 [ 2 ] Bug #1911159 - netpbm-10.93.00 is available https://bugzilla.redhat.com/show_bug.cgi?id=1911159 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f62099fe51' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was found that freeimage, a graphics library, was affected by the following two security issues: CVE-2019-12211 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4593-1
fixed multiple security bugs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-ab7d22a466 2019-11-09 22:37:54.009634 --------------------------------------------------------------------------------Name : gd Product : Fedora 30 Version : 2.2.5 Release : 9.fc30 URL : https://libgd.github.io/ Summary : A graphics library for quick creation of PNG or JPEG images Description : The gd graphics library allows your code to quickly draw images complete with lines, arcs, text, multiple colors, cut and paste from other images, and flood fills, and to write out the result as a PNG or JPEG file. This is particularly useful in Web applications, where PNG and JPEG are two of the formats accepted for inline images by most browsers. Note that gd is not a paint program. --------------------------------------------------------------------------------Update Information: fixed multiple security bugs --------------------------------------------------------------------------------ChangeLog: * Fri Nov 1 2019
Several issues in libgd2, a graphics library that allows to quickly draw images, have been found. . Package : libgd2 Version : 2.1.0-5+deb8u12 CVE ID : CVE-2018-5711 CVE-2018-1000222 CVE-2019-6977 CVE-2019-6978 Several issues in libgd2, a graphics library that allows to quickly draw images, have been found. CVE-2019-6977 A potential double free in gdImage*Ptr() has been reported by Solmaz Salimi (aka. Rooney). CVE-2019-6978 Simon Scannell found a heap-based buffer overflow, exploitable with crafted image data. CVE-2018-1000222 A new double free vulnerabilities in gdImageBmpPtr() has been reported by Solmaz Salimi (aka. Rooney). CVE-2018-5711 Due to an integer signedness error the GIF core parsing function can enter an infinite loop. This will lead to a Denial of Service and exhausted server resources. For Debian 8 "Jessie", these problems have been fixed in version 2.1.0-5+deb8u12. We recommend that you upgrade your libgd2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance libgd2 to version 2.1.0-5+deb8u12 to address vulnerabilities linked to CVE-2018-5711, CVE-2018-1000222, and additional threats.. libgd2 update, graphics library fix, Debian security advisory. . Severity: Important. LinuxSecurity.com Team
This update lowers amount of color artefacts around glyphs when subpixel rendering is enabled for text by using freetype's default LCD filter. It also fixes a crash caused by using of wrong function for freeing of memory (CVE-2018-19876).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-3a195026f5 2018-12-10 02:31:09.366310 --------------------------------------------------------------------------------Name : cairo Product : Fedora 29 Version : 1.16.0 Release : 3.fc29 URL : https://www.cairographics.org/ Summary : A 2D graphics library Description : Cairo is a 2D graphics library designed to provide high-quality display and print output. Currently supported output targets include the X Window System, in-memory image buffers, and image files (PDF, PostScript, and SVG). Cairo is designed to produce consistent output on all output media while taking advantage of display hardware acceleration when available. --------------------------------------------------------------------------------Update Information: This update lowers amount of color artefacts around glyphs when subpixel rendering is enabled for text by using freetype's default LCD filter. It also fixes a crash caused by using of wrong function for freeing of memory (CVE-2018-19876). --------------------------------------------------------------------------------ChangeLog: * Fri Dec 7 2018 Marek Kasik - 1.16.0-3 - Use FT_Done_MM_Var instead of free when available in - cairo_ft_apply_variations * Fri Dec 7 2018 Marek Kasik - 1.16.0-2 - Set default LCD filter to FreeType's default - Resolves: #1645763 * Mon Oct 22 2018 Kalev Lember - 1.16.0-1 - Update to 1.16.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1645763 - ClearType enablement: strong color fringing that is not present in vanilla build from freetype git https://bugzilla.redhat.com/show_bug.cgi?id=1645763 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-3a195026f5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.