Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0623-1

Опубликовано: 09 мар. 2020
Источник: suse-cvrf

Описание

Security update for gd

This update for gd fixes the following issues:

  • CVE-2017-7890: Fixed a buffer over-read into uninitialized memory (bsc#1050241).
  • CVE-2018-14553: Fixed a null pointer dereference in gdImageClone() (bsc#1165471).
  • CVE-2019-11038: Fixed a information disclosure in gdImageCreateFromXbm() (bsc#1140120).

Список пакетов

Container caasp/v4/nginx-ingress-controller:beta1
gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure
gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-BYOS
gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-EC2-HVM
gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-GCE
gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-GCE-BYOS
gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-OCI-BYOS
gd-2.1.0-24.17.1
Image SLES12-SP5-Azure-SAP-BYOS
gd-2.1.0-24.17.1
Image SLES12-SP5-Azure-SAP-On-Demand
gd-2.1.0-24.17.1
Image SLES12-SP5-EC2-SAP-BYOS
gd-2.1.0-24.17.1
Image SLES12-SP5-EC2-SAP-On-Demand
gd-2.1.0-24.17.1
Image SLES12-SP5-GCE-SAP-BYOS
gd-2.1.0-24.17.1
Image SLES12-SP5-GCE-SAP-On-Demand
gd-2.1.0-24.17.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
gd-2.1.0-24.17.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
gd-2.1.0-24.17.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
gd-2.1.0-24.17.1
SUSE Linux Enterprise Desktop 12 SP4
gd-2.1.0-24.17.1
gd-32bit-2.1.0-24.17.1
SUSE Linux Enterprise Server 12 SP4
gd-2.1.0-24.17.1
SUSE Linux Enterprise Server 12 SP5
gd-2.1.0-24.17.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
gd-2.1.0-24.17.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
gd-2.1.0-24.17.1
SUSE Linux Enterprise Software Development Kit 12 SP4
gd-devel-2.1.0-24.17.1
SUSE Linux Enterprise Software Development Kit 12 SP5
gd-devel-2.1.0-24.17.1
SUSE Linux Enterprise Workstation Extension 12 SP4
gd-32bit-2.1.0-24.17.1
SUSE Linux Enterprise Workstation Extension 12 SP5
gd-32bit-2.1.0-24.17.1

Описание

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.


Затронутые продукты
Container caasp/v4/nginx-ingress-controller:beta1:gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-BYOS:gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:gd-2.1.0-24.17.1

Ссылки

Описание

gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).


Затронутые продукты
Container caasp/v4/nginx-ingress-controller:beta1:gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-BYOS:gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:gd-2.1.0-24.17.1

Ссылки

Описание

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.


Затронутые продукты
Container caasp/v4/nginx-ingress-controller:beta1:gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-BYOS:gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:gd-2.1.0-24.17.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:gd-2.1.0-24.17.1

Ссылки