Alpine: gd: security update to 2.2.1-r2

critical Tenable Cloud Security Plugin ID 404531

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to
cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data,
which triggers a heap-based buffer overflow. (CVE-2016-3074)

- Stack consumption vulnerability in GD in PHP before 5.6.12 allows remote attackers to cause a denial of
service via a crafted imagefilltoborder call. (CVE-2015-8874)

- gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x
configurations, allows context-dependent attackers to obtain sensitive information from process memory or
cause a denial of service (stack-based buffer under-read and application crash) via a long name.
(CVE-2016-5116)

- Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before
2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to
cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified
other impact via crafted chunk dimensions in an image. (CVE-2016-5766)

See Also

https://security.alpinelinux.org/vuln/CVE-2015-8874

https://security.alpinelinux.org/vuln/CVE-2016-3074

https://security.alpinelinux.org/vuln/CVE-2016-5116

https://security.alpinelinux.org/vuln/CVE-2016-5766

https://security.alpinelinux.org/vuln/CVE-2016-6128

https://security.alpinelinux.org/vuln/CVE-2016-6161

https://security.alpinelinux.org/vuln/CVE-2016-6214

Plugin Details

Severity: Critical

ID: 404531

Version: Revision 1.24

Type: Local

Published: 10/31/2023

Updated: 3/12/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2016-3074

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 4/21/2016

Reference Information

CVE: CVE-2015-8874, CVE-2016-3074, CVE-2016-5116, CVE-2016-5766, CVE-2016-6128, CVE-2016-6161, CVE-2016-6214

BID: 87087, 90714, 90925, 91509, 91577, 92595