CVE-2018-1000222

Source
Severity Critical
Remote Yes
Type Arbitrary code execution
Description
Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free.
Group Package Affected Fixed Severity Status Ticket
AVG-865 gd 2.2.5-1 Critical Vulnerable
References
https://github.com/libgd/libgd/commit/4b1e18a00ce7c4b7e6919c3b3109a034393b805a
https://github.com/libgd/libgd/issues/447