Search CVE reports
11 – 20 of 58 results
CVE-2017-6362
Medium priorityDouble free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
4 affected packages
libgd2, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |
php7.1 | — | — | — | — | Not in release |
CVE-2017-7890
Medium priorityThe GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image...
4 affected packages
libgd2, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |
php7.1 | — | — | — | — | Not in release |
CVE-2016-9317
Low priorityThe gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image.
3 affected packages
libgd2, php5, php7.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |
CVE-2016-6912
Medium priorityDouble free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
3 affected packages
libgd2, php5, php7.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |
CVE-2016-9933
Low priorityStack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial...
3 affected packages
libgd2, php5, php7.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |
CVE-2016-6906
Low priorityThe read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.
3 affected packages
libgd2, php5, php7.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |
CVE-2016-10168
Medium priorityInteger overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.
4 affected packages
libgd2, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |
php7.1 | — | — | — | — | Not in release |
CVE-2016-10167
Medium priorityThe gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
4 affected packages
libgd2, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |
php7.1 | — | — | — | — | Not in release |
CVE-2016-10166
Medium priorityInteger underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.
3 affected packages
libgd2, php5, php7.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |
CVE-2016-8670
Medium priorityInteger signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of...
3 affected packages
libgd2, php5, php7.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgd2 | — | — | — | — | Fixed |
php5 | — | — | — | — | Not in release |
php7.0 | — | — | — | — | Not affected |