MGASA-2014-0288

Source
https://advisories.mageia.org/MGASA-2014-0288.html
Import Source
https://advisories.mageia.org/MGASA-2014-0288.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0288
Related
Published
2014-07-08T22:44:55Z
Modified
2014-07-08T22:44:48Z
Summary
Updated gd and libgd packages fix security vulnerability
Details

The gdImageCreateFromXpm function in gdxpm.c in the gd image library allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file (CVE-2014-2497).

References
Credits

Affected packages

Mageia:4 / libgd

Package

Name
libgd
Purl
pkg:rpm/mageia/libgd?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.0-3.1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / gd

Package

Name
gd
Purl
pkg:rpm/mageia/gd?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.35-20.1.mga3

Ecosystem specific

{
    "section": "core"
}