Lack of data validation In libgd2
Description
Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 2.0.35.dfsg-1 | ||
debian 13 | 2.0.35.dfsg-1 | ||
debian 11 | - | ||
debian 14 | - | ||
debian 14 | 5.0.2-1 | ||
debian 13 | - | ||
debian 13 | 5.0.2-1 | ||
debian 11 | 5.0.2-1 | ||
debian 12 | - | ||
debian 11 | 2.0.35.dfsg-1 |
1-10 of 13
10
Aliases
1. 2. 3. 4. 5.