ELA-1069-1 libgd2 security update

out-fo-bounds read and NULL pointer dereference

2024-04-07
Packagelibgd2
Version2.1.0-5+deb8u15 (jessie), 2.2.4-2+deb9u6 (stretch)
Related CVEs CVE-2018-14553 CVE-2021-38115 CVE-2021-40812


Several issues have been found in libgd2, a GD Graphics Library. They are related to out-of-bounds reads or NULL pointer derefence allowing denial of service attacks.



For Debian 8 jessie, these problems have been fixed in version 2.1.0-5+deb8u15.

For Debian 9 stretch, these problems have been fixed in version 2.2.4-2+deb9u6.

We recommend that you upgrade your libgd2 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.