Описание
A flaw was found in libgd. Processing a specially crafted GIF file allows a remote attacker to trigger a buffer overflow, resulting in an application crash and a denial of service. Arbitrary code execution is possible in theory, but considered highly unlikely because standard image decompression and pixel manipulation generally destroy the exploit payload.
Отчет
To exploit this flaw, a remote attacker needs to be able to process a crafted GIF file with an application linked to the libgd library. Successful exploitation can result in an application crash, leading to a denial of service, or in arbitrary code execution. However, arbitrary code execution is highly unlikely because standard image decompression and pixel manipulation generally destroy the exploit payload. For these reasons, this vulnerability has been rated with an important severity. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) memory protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gd | Affected | ||
| Red Hat Enterprise Linux 10 | libwmf | Affected | ||
| Red Hat Enterprise Linux 10 | nautilus | Affected | ||
| Red Hat Enterprise Linux 10 | php | Affected | ||
| Red Hat Enterprise Linux 10 | php8.4 | Not affected | ||
| Red Hat Enterprise Linux 6 | gd | Affected | ||
| Red Hat Enterprise Linux 6 | php | Affected | ||
| Red Hat Enterprise Linux 7 | gd | Affected | ||
| Red Hat Enterprise Linux 7 | php | Affected | ||
| Red Hat Enterprise Linux 8 | gd | Affected |
Показывать по
Дополнительная информация
Статус:
8.1 High
CVSS3
8.1 High
CVSS3