SB2017122812 - Double free memory error in gd (Alpine package)
Published: December 28, 2017
Security Bulletin ID
SB2017122812
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Double free memory error (CVE-ID: CVE-2017-6362)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to double free memory error in the gdImagePngPtr function. A remote attacker can submit vectors related to a palette with no colors and cause the service to crash.
Remediation
Install update from vendor's website.