CLSA-2021-1635459219

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635459219.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2021-1635459219
Upstream
Published
2021-10-28T22:13:39Z
Modified
2026-06-04T10:03:25.925809666Z
Summary
Fix CVE(s): CVE-2021-40812, CVE-2021-40145, CVE-2021-38115, CVE-2017-6363
Details
  • SECURITY UPDATE: unhandled memory allocation error in gdImageGd2Ptr
    • debian/patches/CVE-2021-40145.patch: check for non-zero return code from _gdImageGd2
    • CVE-2021-40145
  • SECURITY UPDATE: unhandled value returned from gdPutBuf
    • debian/patches/CVE-2021-40812.patch: handle possible gdPutBuf error in _gdImageBmpCtx and _gdImageWebpCtx CVE-2021-40812
  • SECURITY UPDATE: unhandled value returned from gdGetBuf
    • debian/patches/CVE-2021-38115.patch: handle possible gdGetBuf error in readheadertga CVE-2021-38115
  • SECURITY UPDATE: handle possible heap buffer overread
    • debian/patches/CVE-2017-6363.patch: make sure transparent index is within bounds of the palette CVE-2017-6363
References

Affected packages

TuxCare:Ubuntu:16.04 / libgd-dev

Package

Name
libgd-dev
Purl
pkg:deb/tuxcare/libgd-dev?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.1-4ubuntu0.16.04.13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635459219.json"

TuxCare:Ubuntu:16.04 / libgd-tools

Package

Name
libgd-tools
Purl
pkg:deb/tuxcare/libgd-tools?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.1-4ubuntu0.16.04.13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635459219.json"

TuxCare:Ubuntu:16.04 / libgd3

Package

Name
libgd3
Purl
pkg:deb/tuxcare/libgd3?distro=ubuntu-16.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.1-4ubuntu0.16.04.13

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635459219.json"