CVE-2018-1000222

HIGH

Libgd 2.2.5 - RCE

Title source: llm

Description

Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This vulnerability appears to have been fixed in after commit ac16bdf2d41724b5a65255d4c28fb0ec46bc42f5.

Scores

CVSS v3 8.8
EPSS 0.0121
EPSS Percentile 78.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status published

Affected Products (5)

libgd/libgd
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux

Timeline

Published Aug 20, 2018
Tracked Since Feb 18, 2026