Double free memory error in libgd2 - CVE-2017-6362
Published: April 23, 2018
Vulnerability identifier: #VU12094
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6362
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to double free memory error in the gdImagePngPtr function. A remote attacker can submit vectors related to a palette with no colors and cause the service to crash.
The weakness exists due to double free memory error in the gdImagePngPtr function. A remote attacker can submit vectors related to a palette with no colors and cause the service to crash.
Affected software
libgd2
Debian Linux
Ubuntu
Slackware Linux
Fedora
gd (Alpine package)
libwmf
gd
Debian Linux
Ubuntu
Slackware Linux
Fedora
gd (Alpine package)
libwmf
gd
How to mitigate CVE-2017-6362
Update to version 2.2.5.
gd (Alpine package) - update to 2.2.5-r0
libwmf - addressed in versions 0.2.8.4-53.fc25, 0.2.8.4-53.fc26, 0.2.8.4-53.fc27
gd - addressed in versions 2.2.5-1.fc25, 2.2.5-1.fc26, 2.2.5-1.fc27
libwmf - addressed in versions 0.2.8.4-53.fc25, 0.2.8.4-53.fc26, 0.2.8.4-53.fc27
gd - addressed in versions 2.2.5-1.fc25, 2.2.5-1.fc26, 2.2.5-1.fc27
External References
Related Security Bulletins
- Ubuntu update for GD library
- Ubuntu update for GD library
- Debian update for libgd2
- Slackware Linux update for gd
- Slackware Linux update for libwmf
- Double free memory error in gd (Alpine package)
- Fedora 27 update for gd
- Fedora 25 update for gd
- Fedora 26 update for gd
- Fedora 26 update for libwmf
- Fedora 25 update for libwmf
- Fedora 27 update for libwmf