安全公告详情

NS-SA-2026-0053

2026-07-27 21:21:29

简介

important: glusterfs/gd security update

严重级别

important

主题

An update for glusterfs/gd is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

glusterfs:
gd:


Security Fix(es):
glusterfs: A flaw was found in Gluster, where GlusterFS is vulnerable to a denial of service caused by a stack-based buffer over-read flaw in xlators/mount/fuse/src/fuse-bridge.c. A remote attacker can cause the application to crash by sending a specially-crafted request.(CVE-2023-26253)
glusterfs: bugfix
gd: The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.(CVE-2019-6978)
gd: A data leak was found in gdImageCreateFromGifCtx() in GD Graphics Library used in PHP before 5.6.31 and 7.1.7. An attacker could craft a malicious GIF image and read up to 762 bytes from stack.(CVE-2017-7890)
gd: An integer overflow flaw, leading to a heap-based buffer overflow, was found in gd. A specially crafted image, when converted to webp, could cause the application to crash or potentially execute arbitrary code.(CVE-2016-7568)
gd: A flaw was found in libgd in PHP, where an infinite loop in the GD GIF core parsing function can lead to a denial of service, a remote attacker could exploit this vulnerability to exhaust server resources by providing specially crafted GIF files.(CVE-2018-5711)
gd: ** DISPUTED ** gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and testing purposes." (CVE-2021-40145)
gd: ImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).(CVE-2018-14553)
gd: A NULL pointer dereference flaw was found in the gdImageCreateFromXpm() function of PHP's gd extension. A remote attacker could use this flaw to crash a PHP application using gd via a specially crafted X PixMap (XPM) file.(CVE-2014-2497)
gd: A vulnerability was found in gd. The function dynamicGetbuf() failed to check for out of bounds reads. An attacker could create a crafted image that would lead to a crash or, potentially, information disclosure.(CVE-2016-6911)
gd: ImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.(CVE-2019-6977)
gd: The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.(CVE-2009-3546)
gd: Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.(CVE-2007-0455)
gd: Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This vulnerability appears to have been fixed in after commit ac16bdf2d41724b5a65255d4c28fb0ec46bc42f5.(CVE-2018-1000222)
gd: A vulnerability was found in gd. Integer underflow in a calculation in dynamicGetbuf() was incorrectly handled, leading in some circumstances to an out of bounds write through a very large argument to memcpy(). An attacker could create a crafted image that would lead to a crash or, potentially, code execution.(CVE-2016-8670)
gd: Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.(CVE-2017-6362)
gd: Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.(CVE-2016-3074)
gd: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.11B10.

影响组件

  • glusterfs
  • gd

影响产品

  • CGSL MAIN 6.06

更新包

{"fix":[{"product":"CGSL MAIN 6.06","pkgs":[{"binary":["glusterfs-events-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","glusterfs-extra-xlators-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","glusterfs-resource-agents-8.2-0.t4.zncgsl6_2.t37.0.noarch.rpm","glusterfs-geo-replication-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","glusterfs-server-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","glusterfs-thin-arbiter-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","python3.11-gluster-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libgfapi-devel-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libgfapi0-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libgfchangelog-devel-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libgfchangelog0-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libgfxdr-devel-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libgfrpc-devel-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libgfrpc0-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libgfxdr0-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libglusterd0-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libglusterfs0-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","libglusterfs-devel-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","glusterfs-client-xlators-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","glusterfs-cloudsync-plugins-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","glusterfs-fuse-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","glusterfs-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm","glusterfs-cli-8.2-0.t4.zncgsl6_2.t37.0.x86_64.rpm"],"source":"glusterfs-8.2-0.t4.zncgsl6_2.t37.0.src.rpm"},{"binary":["gd-2.2.5-7.zncgsl6.t6.0.x86_64.rpm"],"source":"gd-2.2.5-7.zncgsl6.t6.0.src.rpm"}]}]}

CVE

参考