9.8
CVSSv3

CVE-2019-6978

Published: 28/01/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that GD incorrectly handled memory when processing certain images. A remote attacker could use this issue with a specially crafted image file to cause GD to crash, resulting in a denial of service, or possibly execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libgd libgd 2.2.5

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

Vendor Advisories

Several security issues were fixed in GD ...
Synopsis Low: libwmf security and bug fix update Type/Severity Security Advisory: Low Topic An update for libwmf is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which g ...
Synopsis Low: libwmf security update Type/Severity Security Advisory: Low Topic An update for libwmf is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a detai ...
Synopsis Moderate: gd security update Type/Severity Security Advisory: Moderate Topic An update for gd is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives ...
Debian Bug report logs - #920645 libgd2: CVE-2019-6977 Package: src:libgd2; Maintainer for src:libgd2 is GD Team <team+gd@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 27 Jan 2019 20:15:01 UTC Severity: grave Tags: patch, security, upstream Found in versions libgd2/224-2, li ...
Debian Bug report logs - #920728 libgd2: CVE-2019-6978 Package: src:libgd2; Maintainer for src:libgd2 is GD Team <team+gd@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 28 Jan 2019 15:51:02 UTC Severity: grave Tags: fixed-upstream, patch, security, upstream Found in versions li ...
The GD Graphics Library (aka LibGD) has a double free in the gdImage*Ptr() functions in gd_gif_outc, gd_jpegc, and gd_wbmpc NOTE: PHP is unaffected (CVE-2019-6978) ...
The GD Graphics Library (aka LibGD) 225 has a double free in the gdImage*Ptr() functions in gd_gif_outc, gd_jpegc, and gd_wbmpc NOTE: PHP is unaffected (CVE-2019-6978) ...
The GD Graphics Library (aka LibGD) 225 has a double free in the gdImage*Ptr() functions in gd_gif_outc, gd_jpegc, and gd_wbmpc NOTE: PHP is unaffected(CVE-2019-6978) ...
The GD Graphics Library (aka LibGD) 225 has a double free in the gdImage*Ptr() functions in gd_gif_outc, gd_jpegc, and gd_wbmpc NOTE: PHP is unaffected ...
The GD Graphics Library (aka LibGD) 225 has a double free in the gdImage*Ptr() functions in gd_gif_outc, gd_jpegc, and gd_wbmpc ...