Executive brief
The GD Graphics Library (libgd), a widely used tool for programmatically creating and manipulating images, contains a vulnerability when processing TIFF files. An attacker can provide a specially crafted TIFF image that, when opened by an application using this library, causes the application to crash. This results in a denial of service, potentially disrupting web services or applications that automate image processing.
Technical details
An out-of-bounds read vulnerability exists in the dynamicGetbuf function within libgd's TIFF processing logic. The root cause is a failure to validate buffer boundaries when handling image data, specifically allowing for negative or excessively large offsets in the dp->pos pointer. When an application calls gdImageCreateFromTiffPtr() with a malformed TIFF file, the library may attempt to read memory outside the allocated buffer, leading to a crash (denial of service). The vulnerability was addressed in version 2.2.4 by adding bounds checks to dynamicGetbuf and ensuring the return value of TIFFReadRGBAImage is properly validated.
Affected products
- libgd libgd before 2.2.4
Timeline
- 2016-08-02: other: Internal patch developed by maintainers
- 2016-10-14: advisory: Debian security advisory DSA-3693-1 published
- 2017-01-26: disclosed: NVD publication date
- 2017-01-18: patched: libgd 2.2.4 released with fix