CVE-2019-6978
Published: 28 January 2019
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.
Priority
CVSS 3 base score: 9.8
Status
Package | Release | Status |
---|---|---|
libgd2 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(2.2.5-5.1)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(2.2.5-5.1)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(2.2.5-4ubuntu0.3)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(2.1.1-4ubuntu0.16.04.11)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Released
(2.1.0-3ubuntu0.11)
|
|
Patches: Upstream: https://github.com/libgd/libgd/commit/553702980ae89c83f2d6e254d62cf82e204956d0 |
||
php5 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Not vulnerable
(uses system gd)
|
|
php7.0 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Not vulnerable
(uses system gd)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
php7.2 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(uses system gd)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
php7.3 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.10 (Groovy Gorilla) |
Does not exist
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
Patches: Upstream: https://github.com/php/php-src/commit/089f7c0bc28d399b0420aa6ef058e4c1c120b2ae |
Notes
Author | Note |
---|---|
mdeslaur | php uses the system libgd2 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6978
- https://usn.ubuntu.com/usn/usn-3900-1
- NVD
- Launchpad
- Debian