CVE-2019-6978: Double Free
Published Jan 15, 2019
·Updated
Last updated 25 August 2025
Other sources
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImagePtr() functions in gdgifout.c, gdjpeg.c, and gdwbmp.c. NOTE: PHP is unaffected.
Affected Software
12 affected componentsFixes available
redhat/libwmf<0:0.2.8.4-44.el7
0:0.2.8.4-44.el7
redhat/libwmf<0:0.2.9-8.el8_0
0:0.2.9-8.el8_0
redhat/gd<0:2.2.5-7.el8
0:2.2.5-7.el8
debian/libgd2<=2.2.4-2+deb9u3, <=2.2.4-2, <=2.2.5-5
2.2.5-5.12.2.4-2+deb9u4
Libgd Libgd=2.2.5
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
debian/libgd2
2.3.0-22.3.0-2+deb11u12.3.3-92.3.3-13
Remediation
Patch Available
Event History
Jan 15, 2019
CVE Published
12:00 AM
Jan 28, 2019
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Jan 31, 2019
Data Sourced
via Red Hat·02:12 PM
DescriptionSeverityAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·04:54 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:54 PM
DescriptionAffected Software
Data Sourced
via Launchpad·04:55 PM
Description
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is CVE-2019-6978?
CVE-2019-6978 is a vulnerability in the GD Graphics Library (LibGD) 2.2.5 that allows for a double free in the gdImage*Ptr() functions.
2
What is the severity of CVE-2019-6978?
The severity of CVE-2019-6978 is critical with a CVSS score of 9.8.
3
What software is affected by CVE-2019-6978?
The affected software includes libwmf, gd, libgd2, and various versions of Debian and Ubuntu Linux distributions.
4
How can I fix CVE-2019-6978?
To fix CVE-2019-6978, you should update to the recommended versions of the affected software packages.
5
Where can I find more information about CVE-2019-6978?
You can find more information about CVE-2019-6978 on the GitHub pages for LibGD and PHP.