VYPR

rpm package

suse/gd&distro=SUSE Linux Enterprise Server 12 SP1

pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1

Vulnerabilities (17)

  • CVE-2016-10168HigMar 15, 2017
    affected < 2.1.0-23.1fixed 2.1.0-23.1

    Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

  • CVE-2016-10167MedMar 15, 2017
    affected < 2.1.0-23.1fixed 2.1.0-23.1

    The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

  • CVE-2016-10166CriMar 15, 2017
    affected < 2.1.0-23.1fixed 2.1.0-23.1

    Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.

  • CVE-2016-6906MedMar 15, 2017
    affected < 2.1.0-23.1fixed 2.1.0-23.1

    The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.

  • CVE-2016-9317MedJan 26, 2017
    affected < 2.1.0-23.1fixed 2.1.0-23.1

    The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image.

  • CVE-2016-6912CriJan 26, 2017
    affected < 2.1.0-23.1fixed 2.1.0-23.1

    Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.

  • CVE-2016-6911MedJan 26, 2017
    affected < 2.1.0-17.1fixed 2.1.0-17.1

    The dynamicGetbuf function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.

  • CVE-2016-9933HigJan 4, 2017
    affected < 2.1.0-20.1fixed 2.1.0-20.1

    Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefi

  • CVE-2016-8670CriJan 4, 2017
    affected < 2.1.0-17.1fixed 2.1.0-17.1

    Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspe

  • CVE-2016-6905MedOct 3, 2016
    affected < 2.1.0-12.1fixed 2.1.0-12.1

    The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA image.

  • CVE-2016-7568CriSep 28, 2016
    affected < 2.1.0-17.1fixed 2.1.0-17.1

    Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafte

  • CVE-2016-6214MedAug 12, 2016
    affected < 2.1.0-12.1fixed 2.1.0-12.1

    gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.

  • CVE-2016-6207MedAug 12, 2016
    affected < 2.1.0-12.1fixed 2.1.0-12.1

    Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

  • CVE-2016-6161MedAug 12, 2016
    affected < 2.1.0-12.1fixed 2.1.0-12.1

    The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.

  • CVE-2016-6132MedAug 12, 2016
    affected < 2.1.0-12.1fixed 2.1.0-12.1

    The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.

  • CVE-2016-6128HigAug 7, 2016
    affected < 2.1.0-12.1fixed 2.1.0-12.1

    The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

  • CVE-2016-5116CriAug 7, 2016
    affected < 2.1.0-12.1fixed 2.1.0-12.1

    gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application cra