SUSE-SU-2017:0468-1

Published: 15 Feb 2017, 06:31
Last modified:04 Feb 2026, 04:06

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

15 Feb 2017, 06:31
Published
Vulnerability first disclosed
04 Feb 2026, 04:06
Last Modified
Vulnerability information updated

Description

Security update for gd This update for gd fixes the following security issues: - CVE-2016-6906: An out-of-bounds read in TGA decompression was fixed which could have lead to crashes. (bsc#1022553) - CVE-2016-6912: Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) allowed remote attackers to have unspecified impact via large width and height values. (bsc#1022284) - CVE-2016-9317: The gdImageCreate function in the GD Graphics Library (aka libgd) allowed remote attackers to cause a denial of service (system hang) via an oversized image. (bsc#1022283) - CVE-2016-10166: A potential unsigned underflow in gd interpolation functions could lead to memory corruption in the GD Graphics Library (aka libgd) (bsc#1022263) - CVE-2016-10167: A denial of service problem in gdImageCreateFromGd2Ctx() could lead to libgd running out of memory even on small files. (bsc#1022264) - CVE-2016-10168: A signed integer overflow in the GD Graphics Library (aka libgd) could lead to memory corruption (bsc#1022265)

Affected Systems

  • susegd&distro=SUSE Linux Enterprise Desktop 12 SP1

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Desktop 12 SP2

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Server 12 SP1

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Server 12 SP2

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Server for Raspberry Pi 12 SP2

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP1

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP2

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Software Development Kit 12 SP1

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Software Development Kit 12 SP2

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Workstation Extension 12 SP1

    < 2.1.0-23.1

  • susegd&distro=SUSE Linux Enterprise Workstation Extension 12 SP2

    < 2.1.0-23.1

References (13)