Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libgd2 | fixed | 2.3.3-14 | package | |
| php8.4 | fixed | 8.4.24-1 | package | |
| php8.4 | fixed | 8.4.24-1~deb13u1 | trixie | package |
| php8.2 | removed | package | ||
| php8.2 | fixed | 8.2.33-1~deb12u1 | bookworm | package |
| php7.4 | removed | package | ||
| php7.4 | fixed | 7.4.33-1+deb11u12 | bullseye | package |
Примечания
Fixed by: https://github.com/php/php-src/commit/b590f0380fda26ed180874a0255f0be078434315 (php-8.4.24)
Связанные уязвимости
CVSS3: 8.1
redhat
около 2 месяцев назад
A flaw was found in libgd. Processing a specially crafted GIF file allows a remote attacker to trigger a buffer overflow, resulting in an application crash and a denial of service. Arbitrary code execution is possible in theory, but considered highly unlikely because standard image decompression and pixel manipulation generally destroy the exploit payload.