Oval Definition:oval:org.opensuse.security:def:56244
Revision Date:2020-12-01Version:1
Title:Security update for gd (Moderate)
Description:



This update for gd fixes the following security issues:

- CVE-2016-6906: An out-of-bounds read in TGA decompression was fixed which could have lead to crashes. (bsc#1022553) - CVE-2016-6912: Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) allowed remote attackers to have unspecified impact via large width and height values. (bsc#1022284) - CVE-2016-9317: The gdImageCreate function in the GD Graphics Library (aka libgd) allowed remote attackers to cause a denial of service (system hang) via an oversized image. (bsc#1022283) - CVE-2016-10166: A potential unsigned underflow in gd interpolation functions could lead to memory corruption in the GD Graphics Library (aka libgd) (bsc#1022263) - CVE-2016-10167: A denial of service problem in gdImageCreateFromGd2Ctx() could lead to libgd running out of memory even on small files. (bsc#1022264) - CVE-2016-10168: A signed integer overflow in the GD Graphics Library (aka libgd) could lead to memory corruption (bsc#1022265)
Family:unixClass:patch
Status:Reference(s):1002639
1019016
1022263
1022264
1022265
1022283
1022284
1022553
1039063
1039064
1039066
1039069
1039661
1042910
1053352
1059554
1083125
1085447
1087102
1090368
1090646
1120943
1160770
953382
953972
954270
954470
960249
962177
964023
965579
965582
966271
968222
977410
981114
CVE-2009-0696
CVE-2009-4022
CVE-2010-3613
CVE-2010-3614
CVE-2010-3615
CVE-2011-0414
CVE-2011-1907
CVE-2011-1910
CVE-2011-2464
CVE-2011-3146
CVE-2011-4313
CVE-2012-1667
CVE-2012-2812
CVE-2012-2813
CVE-2012-2814
CVE-2012-2836
CVE-2012-2837
CVE-2012-2840
CVE-2012-2841
CVE-2012-3817
CVE-2012-3868
CVE-2012-4244
CVE-2012-5166
CVE-2012-5688
CVE-2012-5689
CVE-2013-1881
CVE-2013-1984
CVE-2013-1995
CVE-2013-1998
CVE-2013-2266
CVE-2013-4854
CVE-2013-6401
CVE-2014-0591
CVE-2014-1932
CVE-2014-6272
CVE-2014-8500
CVE-2015-1349
CVE-2015-2695
CVE-2015-4620
CVE-2015-5477
CVE-2015-5722
CVE-2015-7560
CVE-2016-0740
CVE-2016-0775
CVE-2016-10166
CVE-2016-10167
CVE-2016-10168
CVE-2016-1839
CVE-2016-6906
CVE-2016-6912
CVE-2016-9317
CVE-2017-12617
CVE-2017-13166
CVE-2017-5664
CVE-2017-7674
CVE-2017-9047
CVE-2017-9048
CVE-2017-9049
CVE-2017-9050
CVE-2018-0739
CVE-2018-20030
CVE-2018-8781
CVE-2018-8897
CVE-2019-9278
SUSE-SU-2015:2294-1
SUSE-SU-2016:0816-1
SUSE-SU-2016:0935-1
SUSE-SU-2017:0468-1
SUSE-SU-2017:1454-1
SUSE-SU-2017:3279-1
SUSE-SU-2018:0902-1
SUSE-SU-2018:1537-1
SUSE-SU-2020:0457-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • gcab-1.1-lp150.1 is installed
  • OR gcab-lang-1.1-lp150.1 is installed
  • OR libgcab-1_0-0-1.1-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • gpg2-2.2.5-lp151.6.3 is installed
  • OR gpg2-lang-2.2.5-lp151.6.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • krb5-1.6.3-133.49.103 is installed
  • OR krb5-32bit-1.6.3-133.49.103 is installed
  • OR krb5-client-1.6.3-133.49.103 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND Package Information
  • gd-2.1.0-23 is installed
  • OR gd-32bit-2.1.0-23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • bind-9.9.6P1-30 is installed
  • OR bind-chrootenv-9.9.6P1-30 is installed
  • OR bind-doc-9.9.6P1-30 is installed
  • OR bind-libs-9.9.6P1-30 is installed
  • OR bind-libs-32bit-9.9.6P1-30 is installed
  • OR bind-utils-9.9.6P1-30 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • tomcat-8.0.43-10.24 is installed
  • OR tomcat-admin-webapps-8.0.43-10.24 is installed
  • OR tomcat-docs-webapp-8.0.43-10.24 is installed
  • OR tomcat-el-3_0-api-8.0.43-10.24 is installed
  • OR tomcat-javadoc-8.0.43-10.24 is installed
  • OR tomcat-jsp-2_3-api-8.0.43-10.24 is installed
  • OR tomcat-lib-8.0.43-10.24 is installed
  • OR tomcat-servlet-3_1-api-8.0.43-10.24 is installed
  • OR tomcat-webapps-8.0.43-10.24 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • libXi6-1.7.4-9 is installed
  • OR libXi6-32bit-1.7.4-9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • MozillaFirefox-52.8.1esr-109.34 is installed
  • OR MozillaFirefox-devel-52.8.1esr-109.34 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_114-92_64-default-10-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_18-10-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • MozillaFirefox-52.8.1esr-109.34 is installed
  • OR MozillaFirefox-devel-52.8.1esr-109.34 is installed
  • OR MozillaFirefox-translations-52.8.1esr-109.34 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • libudisks2-0-2.1.3-1 is installed
  • OR udisks2-2.1.3-1 is installed
  • OR udisks2-lang-2.1.3-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND mailman-2.1.17-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • openslp-2.0.0-18.17 is installed
  • OR openslp-32bit-2.0.0-18.17 is installed
  • OR openslp-server-2.0.0-18.17 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND python-Pillow-2.7.0-3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • xen-4.7.6_02-43.36 is installed
  • OR xen-doc-html-4.7.6_02-43.36 is installed
  • OR xen-libs-4.7.6_02-43.36 is installed
  • OR xen-libs-32bit-4.7.6_02-43.36 is installed
  • OR xen-tools-4.7.6_02-43.36 is installed
  • OR xen-tools-domU-4.7.6_02-43.36 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • python-certifi-2018.4.16-3.6 is installed
  • OR python-chardet-3.0.4-5.6 is installed
  • OR python-urllib3-1.22-3.20 is installed
  • OR python3-certifi-2018.4.16-3.6 is installed
  • OR python3-chardet-3.0.4-5.6 is installed
  • OR python3-requests-2.20.1-5 is installed
  • OR python3-urllib3-1.22-3.20 is installed
  • BACK