Advisories ยป MGASA-2021-0433

Updated libgd packages fix security vulnerability

Publication date: 23 Sep 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-38115 , CVE-2021-40145

Description

read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through
2.3.2 allows remote attackers to cause a denial of service (out-of-bounds
read) via a crafted TGA file. (CVE-2021-38115)

gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through
2.3.2 has a double free. (CVE-2021-40145)
                

References

SRPMS

8/core