CVE-2021-40812
Summary
| CVE | CVE-2021-40812 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-08 21:15:00 UTC |
| Updated | 2021-09-15 15:07:00 UTC |
| Description | The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBuf return value checks. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Merge pull request #755 from libgd/bug/750 · libgd/libgd@6f51368 · GitHub | MISC | github.com | |
| gdPutBuf return value check · Issue #750 · libgd/libgd · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184557 Debian Security Update for libgd2 (CVE-2021-40812)
- 296061 Oracle Solaris 11.4 Support Repository Update (SRU) 42.113.1 Missing (CPUJAN2022)
- 6000559 Debian Security Update for libgd2 (DLA 3781-1)
- 671145 EulerOS Security Update for gd (EulerOS-SA-2021-2800)
- 671217 EulerOS Security Update for gd (EulerOS-SA-2022-1024)
- 671218 EulerOS Security Update for gd (EulerOS-SA-2022-1004)
- 671327 EulerOS Security Update for gd (EulerOS-SA-2022-1222)
- 671335 EulerOS Security Update for gd (EulerOS-SA-2022-1203)
- 751167 SUSE Enterprise Linux Security Update for gd (SUSE-SU-2021:3214-1)
- 751180 OpenSUSE Security Update for gd (openSUSE-SU-2021:3236-1)
- 900436 Common Base Linux Mariner (CBL-Mariner) Security Update for gd (6270)
- 900876 Common Base Linux Mariner (CBL-Mariner) Security Update for gd (6433)
- 902321 Common Base Linux Mariner (CBL-Mariner) Security Update for gd (6433-1)