UBUNTU-CVE-2017-6363
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-6363
UBUNTU-CVE-2017-6363
Summary:
Details: In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for development and testing purposes.'
References: https://ubuntu.com/security/CVE-2017-6363, https://github.com/libgd/libgd/commit/0be86e1926939a98afbd2f3a23c673dfc4df2a7c, https://github.com/libgd/libgd/commit/2dbd8f6e66b73ed43d9b81a45350922b80f75397, https://github.com/libgd/libgd/issues/383, https://ubuntu.com/security/notices/USN-5068-1, https://www.cve.org/CVERecord?id=CVE-2017-6363
Affected packages
Package
Name: libgd2
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
