FlawAtlas
Search the atlas
SUSE-SU-2020:0623-1 Not scored

Security update for gd

This update for gd fixes the following issues: - CVE-2017-7890: Fixed a buffer over-read into uninitialized memory (bsc#1050241). - CVE-2018-14553: Fixed a null pointer dereference in gdImageClone() (bsc#1165471). - CVE-2019-11038: Fixed a information disclosure in gdImageCreateFromXbm() (bsc#1140120).

Exploit probability Not scored
Published March 9, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 SP4 gd
SUSE:Linux Enterprise Server 12 SP4 gd
SUSE:Linux Enterprise Server 12 SP5 gd
SUSE:Linux Enterprise Server for SAP Applications 12 SP4 gd
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 gd
SUSE:Linux Enterprise Software Development Kit 12 SP4 gd
SUSE:Linux Enterprise Software Development Kit 12 SP5 gd
SUSE:Linux Enterprise Workstation Extension 12 SP4 gd
SUSE:Linux Enterprise Workstation Extension 12 SP5 gd

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2020:0623-1

This update for gd fixes the following issues: - CVE-2017-7890: Fixed a buffer over-read into uninitialized memory (bsc#1050241). - CVE-2018-14553: Fixed a null pointer dereference in gdImageClone() (bsc#1165471). - CVE-2019-11038: Fixed a information disclosure in gdImageCreateFromXbm() (bsc#1140120).

View original source

05 / REFERENCES

Further evidence