[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3556-1 libgd2 -- libgd2

ID: oval:org.secpod.oval:def:602479Date: (C)2016-06-14   (M)2024-04-17
Class: PATCHFamily: unix




Hans Jerry Illikainen discovered that libgd2, a library for programmatic graphics creation and manipulation, suffers of a signedness vulnerability which may result in a heap overflow when processing specially crafted compressed gd2 data. A remote attacker can take advantage of this flaw to cause an application using the libgd2 library to crash, or potentially, to execute arbitrary code with the privileges of the user running the application.

Platform:
Debian 8.x
Debian 7.x
Product:
libgd2-xpm-dev
libgd2-noxpm-dev
libgd3
Reference:
DSA-3556-1
CVE-2016-3074
CVE    1
CVE-2016-3074
CPE    7
cpe:/o:debian:debian_linux:7.x
cpe:/o:debian:debian_linux:8.x
cpe:/a:gd_graphics_library:libgd2-xpm-dev
cpe:/a:gd_graphics_library:libgd3
...

© SecPod Technologies