Description
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 alpine v3.4 | | =2.0.35-r0 || =2.0.35-r1 || =2.0.35-r2 || =2.0.36_rc1-r1 || =2.0.36_rc1-r2 || =2.0.36_rc1-r3 || =2.0.36_rc1-r4 || =2.0.36_rc1-r5 || =2.0.36_rc1-r6 || =2.0.36_rc1-r7 || =2.0.36_rc1-r8 || =2.0.36_rc1-r9 || =2.1.0-r0 || =2.1.0-r1 || =2.1.1-r0 || =2.2.1-r0 || >=0 <2.2.3-r0 | 2.2.3-r0 |
 alpine v3.2 | | =2.0.35-r0 || =2.0.35-r1 || =2.0.35-r2 || =2.0.36_rc1-r1 || =2.0.36_rc1-r2 || =2.0.36_rc1-r3 || =2.0.36_rc1-r4 || =2.0.36_rc1-r5 || =2.0.36_rc1-r6 || =2.0.36_rc1-r7 || =2.0.36_rc1-r8 || =2.0.36_rc1-r9 || =2.1.0-r0 || =2.1.0-r1 || =2.1.1-r0 || =2.1.1-r1 || =2.1.1-r2 || >=0 <2.2.1-r2 | 2.2.1-r2 |
 alpine v3.3 | | =2.0.35-r0 || =2.0.35-r1 || =2.0.35-r2 || =2.0.36_rc1-r1 || =2.0.36_rc1-r2 || =2.0.36_rc1-r3 || =2.0.36_rc1-r4 || =2.0.36_rc1-r5 || =2.0.36_rc1-r6 || =2.0.36_rc1-r7 || =2.0.36_rc1-r8 || =2.0.36_rc1-r9 || =2.1.0-r0 || =2.1.0-r1 || =2.1.1-r0 || =2.1.1-r1 || =2.1.1-r2 || >=0 <2.2.1-r2 | 2.2.1-r2 |
 debian 12 | | | 2.2.2-29-g3c2b605-1 |
 debian 11 | | | 2.2.2-29-g3c2b605-1 |
 debian 14 | | | 2.2.2-29-g3c2b605-1 |
 debian 13 | | | 2.2.2-29-g3c2b605-1 |