PT-2021-7338 · Unknown+4 · Gd Graphics Library+4
Meweez
·
Published
2021-05-26
·
Updated
2025-12-16
·
CVE-2021-40145
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GD Graphics Library (aka LibGD) versions through 2.3.2
Description
The issue is related to a double free in the
gdImageGd2Ptr function in the gd gd2.c component of the GD Graphics Library. This can be exploited by a remote attacker to cause a denial of service. The vendor notes that the GD2 image format is proprietary and should be considered obsolete, only used for development and testing purposes.Recommendations
For versions through 2.3.2, consider updating to a version where this issue is fixed, if available. As a temporary workaround, restrict the use of the
gdImageGd2Ptr function in gd gd2.c to minimize the risk of exploitation. However, since the specific fix version is not provided, and given the vendor's stance on the GD2 image format, it is essential to follow best practices for secure development and testing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Gd Graphics Library
Linuxmint
Ubuntu