Debian Security Advisory

DLA-665-1 libgd2 -- LTS security update

Date Reported:
18 Oct 2016
Affected Packages:
libgd2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-6911, CVE-2016-8670.
More information:
  • CVE-2016-6911

    invalid read in gdImageCreateFromTiffPtr() (most of the code is not present in the Wheezy version)

  • CVE-2016-8670

    Stack Buffer Overflow in GD dynamicGetbuf

For Debian 7 Wheezy, these problems have been fixed in version 2.0.36~rc1~dfsg-6.1+deb7u6.

We recommend that you upgrade your libgd2 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS