The dynamicGetbuf function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/95840 | vdb entry |
https://github.com/libgd/libgd/blob/gd-2.2.4/CHANGELOG.md | issue tracking release notes patch third party advisory |
http://www.debian.org/security/2016/dsa-3693 | vendor advisory |
https://github.com/libgd/libgd/pull/353 | issue tracking third party advisory patch |
https://github.com/libgd/libgd/commit/4859d69e07504d4b0a4bdf9bcb4d9e3769ca35ae | issue tracking third party advisory patch |