MGASA-2016-0258
Advisory lineage Upstream: 3 Downstream: 0
Published: 26 Jul 2016, 19:11
Last modified:16 Apr 2026, 06:24
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
26 Jul 2016, 19:11
Published
Vulnerability first disclosed
16 Apr 2026, 06:24
Last Modified
Vulnerability information updated
Description
Updated libgd packages fix security vulnerability Updated libgd packages fix security vulnerabilities: A read out-of-bounds was found in the parsing of TGA files when the header reports an incorrect size (CVE-2016-6132) or invalid bpp (CVE-2016-6214) or RLE value (upstream issue 248). Integer overflow error within _gdContributionsAlloc() (CVE-2016-6207). A regression in the previous update that caused some packages to fail to build against libgd has also been fixed (mga#18947).
Affected Systems
- mageia•libgd
< 2.2.3-1.1.mga5
References (7)
- https://advisories.mageia.org/MGASA-2016-0258.html
- https://bugs.mageia.org/show_bug.cgi?id=18938
- https://bugs.mageia.org/show_bug.cgi?id=18947
- http://openwall.com/lists/oss-security/2016/06/30/10
- http://openwall.com/lists/oss-security/2016/07/13/12
- http://openwall.com/lists/oss-security/2016/07/12/4
- https://bugs.php.net/bug.php?id=72558