Vulnerability Bulletins

DSA-3556 libgd2 - security update

   
Affected software Debian
 
Hans Jerry Illikainen discovered that libgd2, a library for programmaticgraphics creation and manipulation, suffers of a signednessvulnerability which may result in a heap overflow when processingspecially crafted compressed gd2 data. A remote attacker can takeadvantage of this flaw to cause an application using the libgd2 libraryto crash, or potentially, to execute arbitrary code with the privilegesof the user running the application.

More info:

https://www.debian.org/security/2016/dsa-3556