USN-3213-1: GD library vulnerabilities Ubuntu Security Notice USN-3213-1 28th February, 2017 libgd2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary The GD library could be made to crash or run programs if it processed a specially crafted image file. Software description libgd2 – GD Graphics Library Details Stefan Esser discovered that the GD library incorrectly handled memory whenprocessing certain images. If a user or automated system were tricked intoprocessing a specially crafted image, an attacker could cause a denial ofservice, or possibly execute arbitrary code. This issue only affectedUbuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-10166) It was discovered that the GD library incorrectly handled certain malformedimages. If a user or automated system were tricked into processing aspecially crafted image, an attacker [ more… ]