CVE-2017-6362: Double Free
Published Sep 7, 2017
·Updated
Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
Affected Software
5 affected components
Libgd Libgd=2.2.4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Fedoraproject Fedora=26
Canonical Ubuntu Linux=16.04
Remediation
Patch Available
Event History
Sep 7, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-6362?
CVE-2017-6362 has a high severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2017-6362?
To fix CVE-2017-6362, upgrade libgd2 to version 2.2.5 or later.
3
Which software versions are affected by CVE-2017-6362?
CVE-2017-6362 affects libgd versions prior to 2.2.5, as well as specific Debian and Fedora distributions.
4
Can CVE-2017-6362 be exploited remotely?
Yes, CVE-2017-6362 can be exploited by remote attackers to trigger a denial of service.
5
What components are involved in the CVE-2017-6362 vulnerability?
CVE-2017-6362 is related to the gdImagePngPtr function in the libgd2 library.