Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-40145

Опубликовано: 26 авг. 2021
Источник: debian
EPSS Низкий

Описание

gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and testing purposes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libgd2fixed2.3.3-1package

Примечания

  • https://github.com/libgd/libgd/issues/700

  • https://github.com/libgd/libgd/pull/713

  • https://github.com/libgd/libgd/commit/c5fd25ce0e48fd5618a972ca9f5e28d6d62006af

  • Negligible security impact

EPSS

Процентиль: 70%
0.00645
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and testing purposes.

CVSS3: 7.5
nvd
больше 4 лет назад

gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and testing purposes.

CVSS3: 7.5
msrc
около 4 лет назад

gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete and should only be used for development and testing purposes.

CVSS3: 7.5
github
больше 3 лет назад

** DISPUTED ** gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and testing purposes."

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость компонента gd_gd2.c графической библиотеки LibGD, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 70%
0.00645
Низкий