ALPINE-CVE-2017-6363
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 27 Feb 2020, 05:15
Last modified:03 Dec 2025, 22:41
Vulnerability Summary
Overall Risk (default)
medium
32/100 CVSS Score
8.1 HIGH
3.1 (osv_alpine)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
27 Feb 2020, 05:15
Published
Vulnerability first disclosed
03 Dec 2025, 22:41
Last Modified
Vulnerability information updated
Description
In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for development and testing purposes.'
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Affected Systems
- alpine•gd
< 2.2.5-r4 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0 | < 2.3.0-r0