MGASA-2016-0421

Source
https://advisories.mageia.org/MGASA-2016-0421.html
Import Source
https://advisories.mageia.org/MGASA-2016-0421.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0421
Related
Published
2016-12-22T21:41:01Z
Modified
2016-12-22T21:32:33Z
Summary
Updated libgd packages fixe security vulnerabilities
Details

Ibrahim El-Sayed discovered that the GD library incorrectly handled certain malformed Tiff images. If a user or automated system were tricked into processing a specially crafted Tiff image, an attacker could cause a denial of service (CVE-2016-6911).

Emmanuel Law discovered that the GD library incorrectly handled certain strings when creating images. If a user or automated system were tricked into processing a specially crafted image, an attacker could cause a denial of service, or possibly execute arbitrary code (CVE-2016-8670).

References
Credits

Affected packages