Alpine: gd: security update to 2.2.3-r0

high Tenable Self-Hosted Container Security Plugin ID 404533

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before
2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to
cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified
other impact via crafted chunk dimensions in an image. (CVE-2016-5766)

- The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as
used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an
invalid color index. (CVE-2016-6128)

- The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote
attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file. (CVE-2016-6132)

- Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka
libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or
memory consumption) via unspecified vectors. (CVE-2016-6207)

- gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of
service (out-of-bounds read) via a crafted TGA file. (CVE-2016-6214)

See Also

https://security.alpinelinux.org/vuln/CVE-2016-5766

https://security.alpinelinux.org/vuln/CVE-2016-6128

https://security.alpinelinux.org/vuln/CVE-2016-6132

https://security.alpinelinux.org/vuln/CVE-2016-6207

https://security.alpinelinux.org/vuln/CVE-2016-6214

Plugin Details

Severity: High

ID: 404533

Version: Revision 1.24

Type: Local

Published: 10/31/2023

Updated: 3/12/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2016-5766

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 6/23/2016

Reference Information

CVE: CVE-2016-5766, CVE-2016-6128, CVE-2016-6132, CVE-2016-6207, CVE-2016-6214

BID: 91509, 91520, 92080, 92595