First published: Mon Aug 27 2018(Updated: )
It was discovered that GD incorrectly handled certain images. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-1000222) It was discovered that GD incorrectly handled certain GIF files. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-5711)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libgd-tools | <2.2.5-4ubuntu0.2 | 2.2.5-4ubuntu0.2 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/libgd3 | <2.2.5-4ubuntu0.2 | 2.2.5-4ubuntu0.2 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/libgd-tools | <2.1.1-4ubuntu0.16.04.10 | 2.1.1-4ubuntu0.16.04.10 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/libgd3 | <2.1.1-4ubuntu0.16.04.10 | 2.1.1-4ubuntu0.16.04.10 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/libgd-tools | <2.1.0-3ubuntu0.10 | 2.1.0-3ubuntu0.10 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/libgd3 | <2.1.0-3ubuntu0.10 | 2.1.0-3ubuntu0.10 |
Ubuntu Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this GD vulnerability is CVE-2018-1000222.
This GD vulnerability allows attackers to execute arbitrary code.
This GD vulnerability can be exploited by handling certain images or GIF files.
The software versions affected by this GD vulnerability are libgd-tools 2.2.5-4ubuntu0.2 and libgd3 2.2.5-4ubuntu0.2 in Ubuntu 18.04; libgd-tools 2.1.1-4ubuntu0.16.04.10 and libgd3 2.1.1-4ubuntu0.16.04.10 in Ubuntu 16.04; and libgd-tools 2.1.0-3ubuntu0.10 and libgd3 2.1.0-3ubuntu0.10 in Ubuntu 14.04.
To fix this GD vulnerability, update the libgd-tools and libgd3 packages to the remedy versions specified for the respective Ubuntu versions.