USN-3389-2: GD vulnerability
14 August 2017
The system could be made to expose sensitive information.
- libgd2 - GD Graphics Library
USN-3389-1 fixed a vulnerability in GD Graphics Library.
This update provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
A vulnerability was discovered in GD Graphics Library (aka libgd),
as used in PHP that does not zero colorMap arrays before use.
A specially crafted GIF image could use the uninitialized tables to
read bytes from the top of the stack.
- USN-3389-1: libgd2-xpm-dev, libgd3, libgd2-noxpm-dev, libgd-dev, libgd-tools, libgd2