Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-5443

Опубликовано: 16 дек. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-5443: gd security update (MODERATE)

[2.0.35-27]

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

gd

2.0.35-27.el7_9

gd-devel

2.0.35-27.el7_9

gd-progs

2.0.35-27.el7_9

Oracle Linux x86_64

gd

2.0.35-27.el7_9

gd-devel

2.0.35-27.el7_9

gd-progs

2.0.35-27.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.

CVSS3: 5.6
redhat
почти 9 лет назад

Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.

CVSS3: 8.8
nvd
почти 9 лет назад

Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.

CVSS3: 8.8
debian
почти 9 лет назад

Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD G ...

CVSS3: 8.8
github
около 3 лет назад

Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.

Уязвимость ELSA-2020-5443