~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2016-9933

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2017-01-04
2
 
Candidate: CVE-2016-9933
3
 
PublicDate: 2017-01-04
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9933
6
 
 http://www.openwall.com/lists/oss-security/2016/12/12/2
7
 
 https://usn.ubuntu.com/usn/usn-3213-1
8
 
Description:
9
 
 Stack consumption vulnerability in the gdImageFillToBorder function in gd.c
10
 
 in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before
11
 
 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of
12
 
 service (segmentation violation) via a crafted imagefilltoborder call that
13
 
 triggers use of a negative color value.
14
 
Ubuntu-Description:
15
 
Notes:
16
 
 mdeslaur> php uses the system libgd2
17
 
Bugs:
18
 
 https://bugs.php.net/bug.php?id=72696
19
 
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=849038
20
 
Priority: low
21
 
Discovered-by:
22
 
Assigned-to: mdeslaur
23
 
 
24
 
Patches_libgd2:
25
 
 upstream: https://github.com/libgd/libgd/commit/77f619d48259383628c3ec4654b1ad578e9eb40e
26
 
upstream_libgd2: released (2.2.2)
27
 
precise_libgd2: released (2.0.36~rc1~dfsg-6ubuntu2.4)
28
 
trusty_libgd2: released (2.1.0-3ubuntu0.6)
29
 
vivid/stable-phone-overlay_libgd2: DNE
30
 
vivid/ubuntu-core_libgd2: DNE
31
 
xenial_libgd2: released (2.1.1-4ubuntu0.16.04.6)
32
 
yakkety_libgd2: released (2.2.1-1ubuntu3.3)
33
 
devel_libgd2: not-affected (2.2.3-87-gd0fec80-3)
34
 
 
35
 
Patches_php5:
36
 
upstream_php5: needs-triage
37
 
precise_php5: not-affected (uses system gd)
38
 
trusty_php5: not-affected (uses system gd)
39
 
vivid/ubuntu-core_php5: DNE
40
 
vivid/stable-phone-overlay_php5: DNE
41
 
xenial_php5: DNE
42
 
yakkety_php5: DNE
43
 
devel_php5: DNE
44
 
 
45
 
Patches_php7.0:
46
 
upstream_php7.0: needs-triage
47
 
precise_php7.0: DNE
48
 
trusty_php7.0: DNE
49
 
vivid/ubuntu-core_php7.0: DNE
50
 
vivid/stable-phone-overlay_php7.0: DNE
51
 
xenial_php7.0: not-affected (uses system gd)
52
 
yakkety_php7.0: not-affected (uses system gd)
53
 
devel_php7.0: not-affected (uses system gd)