Double Free in libgd2 - CVE-2019-6978
Published: February 6, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. A remote attacker can trick the victim into opening a specially crafted input, trigger double free error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
Slackware Linux
Opensuse
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Fedora
libwmf (Red Hat package)
libgd2 (Ubuntu package)
libgd2 (Debian package)
gd (Alpine package)
SUSE Linux Enterprise Module for Packagehub Subpackages
libwmf
libwmf-tools-debuginfo
libwmf-0_2-7
libwmf-0_2-7-debuginfo
libwmf-devel
libwmf-debugsource
libwmf-gnome
libwmf-gnome-debuginfo
libwmf-tools
libwmf-gnome-32bit
libwmf-0_2-7-32bit-debuginfo
libwmf-0_2-7-32bit
libwmf-gnome-32bit-debuginfo
gd (Red Hat package)
gd
Data Computing Appliance (DCA)
Flex System Chassis Management Module (CMM)
How to mitigate CVE-2019-6978
libgd2 (Ubuntu package) - addressed in versions 2.1.0-3ubuntu0.11, 2.1.1-4ubuntu0.16.04.11, 2.2.5-4ubuntu0.3, 2.2.5-4ubuntu1.1
libgd2 (Debian package) - update to 2.2.4-2+deb9u4
gd (Alpine package) - update to 2.2.5-r2
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
libwmf - addressed in versions 0.2.12-1.fc28, 0.2.12-1.fc29
libwmf-tools-debuginfo - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-0_2-7 - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-0_2-7-debuginfo - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-devel - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-debugsource - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-gnome - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-gnome-debuginfo - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-tools - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-gnome-32bit - update to 0.2.12-150000.4.4.1
libwmf-0_2-7-32bit-debuginfo - update to 0.2.12-150000.4.4.1
libwmf-0_2-7-32bit - update to 0.2.12-150000.4.4.1
libwmf-gnome-32bit-debuginfo - update to 0.2.12-150000.4.4.1
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c
gd (Red Hat package) - update to 2.2.5-7.el8
gd - addressed in versions 2.2.5-8.fc29, 2.2.5-9.fc30, 2.2.5-10.fc31, 2.3.0-1.fc32
External References
Related Security Bulletins
- Debian update for libgd2
- OpenSUSE Linux update for php7
- Ubuntu update for GD
- OpenSUSE Linux update for gd
- OpenSUSE Linux update for gd
- Amazon Linux AMI update for libwmf
- Gentoo update for GD
- Red Hat update for libwmf
- Slackware Linux update for gd
- Double Free in gd (Alpine package)
- Red Hat Enterprise Linux 7 update for libwmf
- Red Hat Enterprise Linux 8 update for gd
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- SUSE update for libwmf
- SUSE update for libwmf
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Fedora 29 update for libwmf
- Fedora 28 update for libwmf
- Fedora 29 update for gd
- Fedora 30 update for gd
- Fedora 31 update for gd
- Fedora 32 update for gd