CVE-2017-6362Double Free in Ubuntu Linux

Severity
7.5HIGHNVD
EPSS
0.4%
top 38.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 7
Latest updateMay 17

Description

Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDlibgd/libgd2.2.4

Also affects: Debian Linux 8.0, 9.0, Fedora 26, Ubuntu Linux 16.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hc3p-jvff-jfw5: Double free vulnerability in the gdImagePngPtr function in libgd2 before 22022-05-17
OSV
CVE-2017-6362: Double free vulnerability in the gdImagePngPtr function in libgd2 before 22017-09-07
CVEList
CVE-2017-6362: Double free vulnerability in the gdImagePngPtr function in libgd2 before 22017-09-07

📋Vendor Advisories

4
Ubuntu
GD library vulnerability2017-09-05
Ubuntu
GD library vulnerability2017-09-05
Red Hat
gd: Double free in the gdImagePngPtr function2017-08-30
Debian
CVE-2017-6362: libgd2 - Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 a...2017

💬Community

2
Bugzilla
CVE-2017-6362 gd: Double free in the gdImagePngPtr function2017-09-08
Bugzilla
CVE-2017-6362 libwmf: gd: Double free in the gdImagePngPtr function [fedora-all]2017-09-08