First published: Thu Feb 27 2020(Updated: )
** DISPUTED ** In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for development and testing purposes.'"
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libgd | <=2.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6363 is a vulnerability in the GD Graphics Library (LibGD) that allows a heap-based buffer over-read in tiffWriter.
The severity of CVE-2017-6363 is high, with a CVSS score of 8.1.
CVE-2017-6363 allows an attacker to perform a heap-based buffer over-read in tiffWriter, potentially leading to information disclosure or denial of service.
Yes, the vendor has released a fix for CVE-2017-6363 in LibGD. It is recommended to update to version 2.2.6 or later.
You can find more information about CVE-2017-6363 on the GitHub issue page: https://github.com/libgd/libgd/issues/383