REDHAT-BUG-1600727: Null Pointer Dereference
A flaw was found in gd as shipped with Fedora. Cloning a image with style "attached", triggers a NULL pointer dereference in 'gdImageClone' leading to denial of service.
Affected versions: gd-2.2.5 gd-2.2.4 gd-2.2.3 gd-2.2.2 gd-2.2.1 gd-2.2.0 gd-2.1.1 gd-2.1.0 gd-2.1.0-rc2
References:
https://bugzilla.redhat.com/showbug.cgi?id=1599032
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1600727?
The vulnerability is classified as a denial of service due to a NULL pointer dereference in the gdImageClone function.
How do I fix REDHAT-BUG-1600727?
To fix REDHAT-BUG-1600727, you should update gd to a version that is not affected, specifically above 2.2.5.
Which versions are affected by REDHAT-BUG-1600727?
Affected versions include gd versions from 2.1.0-rc2 up to 2.2.5.
What software is impacted by REDHAT-BUG-1600727?
The vulnerability affects the gd library as packaged in Fedora distributions.
What causes the issue in REDHAT-BUG-1600727?
The issue is caused by a flaw in the gd library that leads to a NULL pointer dereference when cloning images with the 'attached' style.