Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2017.0283 libgd2 security update 1 February 2017 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: libgd2 Publisher: Debian Operating System: Debian GNU/Linux 8 Impact/Access: Execute Arbitrary Code/Commands -- Existing Account Denial of Service -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2016-10168 CVE-2016-10167 CVE-2016-10166 CVE-2016-9317 CVE-2016-6912 CVE-2016-6906 Original Bulletin: http://www.debian.org/security/2017/dsa-3777 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-3777-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso January 31, 2017 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : libgd2 CVE ID : CVE-2016-6906 CVE-2016-6912 CVE-2016-9317 CVE-2016-10166 CVE-2016-10167 CVE-2016-10168 Multiple vulnerabilities have been discovered in libgd2, a library for programmatic graphics creation and manipulation, which may result in denial of service or potentially the execution of arbitrary code if a malformed file is processed. For the stable distribution (jessie), these problems have been fixed in version 2.1.0-5+deb8u9. For the testing distribution (stretch) and the unstable distribution (sid), these problems have been fixed in version 2.2.4-1. We recommend that you upgrade your libgd2 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAliQ2gZfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SViBAAilj6u75zRlTUX0RbCO/4Ag65MobTXcABw+0pku4EQpzjL7ddCyHsyadc GPKqw/NiVNY6YMOQQvosjjsLNmAUY7TDUCjNu5Zwb+ql0QGG7cMuftJDhZvKMVh7 NGgYGjzjkOss4NugYEJEV7DuLKcHRzpTM7SwD6r6lkN2h6xpVTn/eFgunoJa1zL/ rYInsjcihPaQXICeHICYeNlIzZncpdgODa026dA7gdGSnKDZvjHjL9Mq5Hj7Iv/9 ExzwfaouUqnW3v7BwRi8b/noIS+Bw/Y64LtJazI0CBMVNr0wjHbFBxn8KfNe7cn3 d7meZZPnB0tb7iKFmHsYSfBy8hJoPhxaaN9Lqzp4UVdNGrCRGHLmvBqpmFp4PE18 M8YE0bM2vLwX0KzGkQCEzg2EnJVew6VT0KUw3duR+SlkqgmKL2S6HYUJCw58xXOr jeikes9G59SMdmp52gLAJB2YpYdudDSYIFIYgSabFJqqbeBZlUBL1Q46w+aKRXb1 Jak6oavK4wFrUHPa1RM8N9FidCzquBlQR0wLhgiBszOEe2Cd+ovsnT0xbMaq0HdF m2o5bDXJbrZ+N5iJnD6HmT7qZSciVosl4ahdgRvZPTC1RTADRUpW279ph4Kz1q2l ixGhE601/PWMn7m+5a32fXsuR5BzE7fRo9FBqgk57LLXI87ExCg= =jiq4 - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBWJEqWYx+lLeg9Ub1AQgtiw/8CmMw7sHBCBJSWTIEwHX3qHRjoehlamFP PwXJNWzo7Kpk3CWFNB5D3rcNR1yIlAWwnSO0NhlRsnL+0jyJmyRRwLOzo2HE366S gEUQPWkiN2WMcuzmNsvrXko544Fhro8mG4MTHfxdt6JDtcfuSm/qAHK4zibvEpkR I5dF00FOkY+RGyIjMD9YixDQC8tMl+1zV8wqUYylxeecHp5s82TajXf0UPMxZypY FIUv2PHospKAchAPQOsStHUF1X3rlIpP+SLrCMQcIACEudgxwCwwmSBMQ00Fu048 TXq6Mt2fh+l2gHZl0EQh2KTHRIm0p+qcMaCjYtDODvcWzpDR79UnxWTMVflk5cBf S6QvrEXHXzrd2b4FGsjQIPOxiyPpvN/mbL1t7u9Y9Af3Yz271i8OGpM/HwfZQJHu KbVzczAmf3tla2nt5HDy4RduxSfYxeIjatR0SZw9W+IaGhFFGX58LiZsjQ8iuV3y 2JSIVKrRBB4fPh7pgHO181+1MdP6/OztSmmxGJ4YIxSh/BA4mcj82EC5Dl3uf1Ja 9C+z5ueNhOmThdWQpldNpj5oFxK0R/Wy6ib/W2aimCuAfgw0tlGAD+NDXRQ14P2Z yCDokO6BshWiG627o61EgM97T5nzh+fwQTAgtev5SF465hWnT6IrbipwB7d0oHd9 JOt2LneuQ2g= =SzPE -----END PGP SIGNATURE-----