Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0866-1

Опубликовано: 24 мар. 2015
Источник: suse-cvrf

Описание

Security update for gd

The graphics drawing library gd was updated to fix one security issue.

The following vulnerability was fixed:

  • possible buffer read overflow (CVE-2014-9709)

Список пакетов

SUSE Linux Enterprise Desktop 12
gd-2.1.0-5.1
gd-32bit-2.1.0-5.1
SUSE Linux Enterprise Server 12
gd-2.1.0-5.1
SUSE Linux Enterprise Server for SAP Applications 12
gd-2.1.0-5.1
SUSE Linux Enterprise Software Development Kit 12
gd-devel-2.1.0-5.1
SUSE Linux Enterprise Workstation Extension 12
gd-32bit-2.1.0-5.1

Описание

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:gd-2.1.0-5.1
SUSE Linux Enterprise Desktop 12:gd-32bit-2.1.0-5.1
SUSE Linux Enterprise Server 12:gd-2.1.0-5.1
SUSE Linux Enterprise Server for SAP Applications 12:gd-2.1.0-5.1

Ссылки