New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 3.6
Synopsis
The remote openSUSE host is missing a security update.
Description
This update for gd fixes the following issues :
- CVE-2016-6214: Buffer over-read issue when parsing crafted TGA file [bsc#991436]
- CVE-2016-6132: read out-of-bands was found in the parsing of TGA files using libgd [bsc#987577]
- CVE-2016-6128: Invalid color index not properly handled [bsc#991710]
- CVE-2016-6207: Integer overflow error within
_gdContributionsAlloc() [bsc#991622]
- CVE-2016-6161: global out of bounds read when encoding gif from malformed input withgd2togif [bsc#988032]
Solution
Update the affected gd packages.