CVE-2019-6978

Name
CVE-2019-6978
Description
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/php/php-src/commit/089f7c0bc28d399b0420aa6ef058e4c1c120b2ae
Patch https://github.com/libgd/libgd/issues/492
Patch https://github.com/libgd/libgd/commit/553702980ae89c83f2d6e254d62cf82e204956d0
Mailing List https://lists.debian.org/debian-lts-announce/2019/01/msg00028.html
Third Party Advisory https://www.debian.org/security/2019/dsa-4384
Third Party Advisory https://usn.ubuntu.com/3900-1/
Third Party Advisory https://security.gentoo.org/glsa/201903-18
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00025.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00031.html
REDHAT https://access.redhat.com/errata/RHSA-2019:2722
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TEYUUOW75YD3DENIPYMO263E6NL2NFHI/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WRUPZVT2MWFUEMVGTRAGDOBHLNMGK5R/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TTXSLRZI5BCQT3H5KALG3DHUWUMNPDX2/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libgd:libgd:2.2.5:*:*:*:*:*:*:* libgd == None == 2.2.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gd edge-main 2.2.5-r2 None fixed
gd 3.22-main 2.2.5-r2 None fixed
gd 3.21-main 2.2.5-r2 None fixed
gd 3.20-main 2.2.5-r2 None fixed
gd 3.19-main 2.2.5-r2 None fixed
gd 3.18-main 2.2.5-r2 None fixed
gd 3.17-main 2.2.5-r2 None fixed
gd 3.12-main 2.2.5-r2 None fixed
gd 3.11-main 2.2.5-r2 None fixed
gd 3.10-main 2.2.5-r2 None fixed