Описание
In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for development and testing purposes.'
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 2.2.5-4ubuntu0.5 |
| devel | not-affected | |
| eoan | ignored | end of life |
| esm-infra-legacy/trusty | released | 2.1.0-3ubuntu0.11+esm2 |
| esm-infra/bionic | released | 2.2.5-4ubuntu0.5 |
| esm-infra/focal | released | 2.2.5-5.2ubuntu2.1 |
| esm-infra/xenial | released | 2.1.1-4ubuntu0.16.04.12+esm1 |
| focal | released | 2.2.5-5.2ubuntu2.1 |
| groovy | ignored | end of life |
| hirsute | not-affected |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| eoan | DNE | |
| esm-infra-legacy/trusty | not-affected | uses system gd |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE | |
| impish | DNE | |
| jammy | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| eoan | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| esm-infra/xenial | not-affected | uses system gd |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE | |
| impish | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | uses system gd |
| devel | DNE | |
| eoan | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | uses system gd |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE | |
| impish | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| eoan | not-affected | uses system gd |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE | |
| impish | DNE | |
| jammy | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| eoan | DNE | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | not-affected | uses system gd |
| focal | not-affected | uses system gd |
| groovy | not-affected | uses system gd |
| hirsute | not-affected | uses system gd |
| impish | DNE | |
| jammy | DNE |
Показывать по
Ссылки на источники
EPSS
5.8 Medium
CVSS2
8.1 High
CVSS3
Связанные уязвимости
In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for development and testing purposes.'
In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap- ...
** DISPUTED ** In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for development and testing purposes.'"
Уязвимость функции tiffWriter компонента gd_tiff.c графической библиотеки LibGD, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
EPSS
5.8 Medium
CVSS2
8.1 High
CVSS3