~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2016-10168

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2016-12-31
2
 
Candidate: CVE-2016-10168
3
 
PublicDate: 2017-03-15
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10168
6
 
 http://www.openwall.com/lists/oss-security/2017/01/26/1
7
 
 https://usn.ubuntu.com/usn/usn-3213-1
8
 
Description:
9
 
 Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before
10
 
 2.2.4 allows remote attackers to have unspecified impact via vectors
11
 
 involving the number of horizontal and vertical chunks in an image.
12
 
Ubuntu-Description:
13
 
Notes:
14
 
 mdeslaur> php uses the system libgd2
15
 
Bugs:
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to: mdeslaur
19
 
 
20
 
Patches_libgd2:
21
 
 upstream: https://github.com/libgd/libgd/commit/69d2fd2c597ffc0c217de1238b9bf4d4bceba8e6
22
 
upstream_libgd2: needed
23
 
precise_libgd2: released (2.0.36~rc1~dfsg-6ubuntu2.4)
24
 
trusty_libgd2: released (2.1.0-3ubuntu0.6)
25
 
vivid/stable-phone-overlay_libgd2: DNE
26
 
vivid/ubuntu-core_libgd2: DNE
27
 
xenial_libgd2: released (2.1.1-4ubuntu0.16.04.6)
28
 
yakkety_libgd2: released (2.2.1-1ubuntu3.3)
29
 
devel_libgd2: not-affected (2.2.4-2)
30
 
 
31
 
Patches_php5:
32
 
upstream_php5: released (5.6.30)
33
 
precise_php5: not-affected (uses system gd)
34
 
trusty_php5: not-affected (uses system gd)
35
 
vivid/ubuntu-core_php5: DNE
36
 
vivid/stable-phone-overlay_php5: DNE
37
 
xenial_php5: DNE
38
 
yakkety_php5: DNE
39
 
devel_php5: DNE
40
 
 
41
 
Patches_php7.0:
42
 
upstream_php7.0: released (7.0.15)
43
 
precise_php7.0: DNE
44
 
trusty_php7.0: DNE
45
 
vivid/ubuntu-core_php7.0: DNE
46
 
vivid/stable-phone-overlay_php7.0: DNE
47
 
xenial_php7.0: not-affected (uses system gd)
48
 
yakkety_php7.0: not-affected (uses system gd)
49
 
devel_php7.0: not-affected (uses system gd)
50
 
 
51
 
Patches_php7.1:
52
 
upstream_php7.1: released (7.1.1)
53
 
precise_php7.1: DNE
54
 
trusty_php7.1: DNE
55
 
vivid/ubuntu-core_php7.1: DNE
56
 
vivid/stable-phone-overlay_php7.1: DNE
57
 
xenial_php7.1: DNE
58
 
yakkety_php7.1: DNE
59
 
devel_php7.1: not-affected (uses system gd)