VYPR

rpm package

suse/gd&distro=SUSE Linux Enterprise Module for Package Hub 15 SP1

pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP1

Vulnerabilities (2)

  • CVE-2018-14553Feb 11, 2020
    affected < 2.2.5-4.14.1fixed 2.2.5-4.14.1

    gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).

  • CVE-2019-11038Jun 18, 2019
    affected < 2.2.5-4.14.1fixed 2.2.5-4.14.1

    When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value o