CVE-2021-40812: Medium severity Libgd Libgd vulnerability
Last updated 15 November 2024
Other sources
The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBuf return value checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libgd2to a version that resolves this vulnerability.Fixed in 2.3.3-9Fixed in 2.3.3-12 - Upgrade
Upgrade
GD Graphics Library (LibGD)to a version that resolves this vulnerability.Fixed in 2.3.2
Event History
Frequently Asked Questions
What is CVE-2021-40812?
CVE-2021-40812 is a vulnerability in the GD Graphics Library (LibGD) that allows for an out-of-bounds read due to the lack of certain return value checks in gdGetBuf and gdPutBuf.
How severe is CVE-2021-40812?
CVE-2021-40812 has a severity rating of 6.5, making it a medium severity vulnerability.
What software is affected by CVE-2021-40812?
The LibGD library version up to and including 2.3.2 is affected by CVE-2021-40812.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-40812?
The CWE ID for CVE-2021-40812 is CWE-125, which corresponds to Out-of-bounds Read.
How can I mitigate CVE-2021-40812?
To mitigate CVE-2021-40812, it is recommended to update LibGD to a version that includes the fix, such as version 2.3.3 or later.