Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000222

Опубликовано: 15 июл. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This vulnerability appears to have been fixed in after commit ac16bdf2d41724b5a65255d4c28fb0ec46bc42f5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gdNot affected
Red Hat Enterprise Linux 5libwmfNot affected
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6gdNot affected
Red Hat Enterprise Linux 6libwmfNot affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7gdNot affected
Red Hat Enterprise Linux 7libwmfNot affected
Red Hat Enterprise Linux 7phpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1621953gd: Double free in src/gd_bump.c:gdImageBmpPtr() via crafted JPEG

EPSS

Процентиль: 79%
0.0128
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This vulnerability appears to have been fixed in after commit ac16bdf2d41724b5a65255d4c28fb0ec46bc42f5.

CVSS3: 8.8
nvd
больше 7 лет назад

Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This vulnerability appears to have been fixed in after commit ac16bdf2d41724b5a65255d4c28fb0ec46bc42f5.

CVSS3: 8.8
debian
больше 7 лет назад

Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability ...

suse-cvrf
больше 7 лет назад

Security update for gd

suse-cvrf
больше 7 лет назад

Security update for gd

EPSS

Процентиль: 79%
0.0128
Низкий

5.3 Medium

CVSS3