Description
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 14 | | | 2.2.4-1 |
 alpine v3.3 | | =2.0.35-r0 || =2.0.35-r1 || =2.0.35-r2 || =2.0.36_rc1-r1 || =2.0.36_rc1-r2 || =2.0.36_rc1-r3 || =2.0.36_rc1-r4 || =2.0.36_rc1-r5 || =2.0.36_rc1-r6 || =2.0.36_rc1-r7 || =2.0.36_rc1-r8 || =2.0.36_rc1-r9 || =2.1.0-r0 || =2.1.0-r1 || =2.1.1-r0 || =2.1.1-r1 || =2.1.1-r2 || >=0 <2.2.4-r0 | 2.2.4-r0 |
 alpine v3.4 | | =2.0.35-r0 || =2.0.35-r1 || =2.0.35-r2 || =2.0.36_rc1-r1 || =2.0.36_rc1-r2 || =2.0.36_rc1-r3 || =2.0.36_rc1-r4 || =2.0.36_rc1-r5 || =2.0.36_rc1-r6 || =2.0.36_rc1-r7 || =2.0.36_rc1-r8 || =2.0.36_rc1-r9 || =2.1.0-r0 || =2.1.0-r1 || =2.1.1-r0 || =2.2.1-r0 || =2.2.3-r0 || =2.2.3-r1 || >=0 <2.2.4-r0 | 2.2.4-r0 |
 alpine v3.5 | | =2.0.35-r0 || =2.0.35-r1 || =2.0.35-r2 || =2.0.36_rc1-r1 || =2.0.36_rc1-r2 || =2.0.36_rc1-r3 || =2.0.36_rc1-r4 || =2.0.36_rc1-r5 || =2.0.36_rc1-r6 || =2.0.36_rc1-r7 || =2.0.36_rc1-r8 || =2.0.36_rc1-r9 || =2.1.0-r0 || =2.1.0-r1 || =2.1.1-r0 || =2.2.1-r0 || =2.2.3-r0 || =2.2.3-r1 || >=0 <2.2.4-r0 | 2.2.4-r0 |
 debian 12 | | | 2.2.4-1 |
 debian 11 | | | 2.2.4-1 |
 debian 13 | | | 2.2.4-1 |