Lucene search

K
mageiaGentoo FoundationMGASA-2016-0242
HistoryJul 05, 2016 - 6:47 p.m.

Updated libgd packages fix security vulnerability

2016-07-0518:47:08
Gentoo Foundation
advisories.mageia.org
31

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.242 Low

EPSS

Percentile

96.6%

Stack overflow with imagefilltoborder (CVE-2015-8874). Integer Overflow in _gd2GetHeader() resulting in heap overflow (CVE-2016-5766). Integer Overflow in gdImagePaletteToTrueColor() resulting in heap overflow (CVE-2016-5767). Improperly handling invalid color index in gdImageCropThreshold() could result in denial of service (CVE-2016-6128).

OSVersionArchitecturePackageVersionFilename
Mageia5noarchlibgd< 2.2.2-1.1libgd-2.2.2-1.1.mga5

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.242 Low

EPSS

Percentile

96.6%