MGASA-2020-0134

Source
https://advisories.mageia.org/MGASA-2020-0134.html
Import Source
https://advisories.mageia.org/MGASA-2020-0134.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0134
Related
Published
2020-03-08T22:37:31Z
Modified
2020-03-08T22:14:40Z
Summary
Updated libgd packages fix security vulnerability
Details

The updated packages fix a security vulnerability:

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code. (CVE-2019-11038)

References
Credits

Affected packages

Mageia:7 / libgd

Package

Name
libgd
Purl
pkg:rpm/mageia/libgd?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.5-5.2.mga7

Ecosystem specific

{
    "section": "core"
}