[3.5] gd: Double free in src/gd_bump.c:gdImageBmpPtr() via crafted JPEG (CVE-2018-1000222)
Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability
in gdImageBmpPtr Function that can result
in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free.
This vulnerability appears to have been fixed in after commit ac16bdf2d41724b5a65255d4c28fb0ec46bc42f5.
(from redmine: issue id 9502, created on 2018-10-02, closed on 2018-10-04)
- parent #9497 (closed)
- Revision 1b9e8e25 by Natanael Copa on 2018-10-02T14:11:23Z:
main/gd: backport security fix for CVE-2018-1000222 fixes #9502