CVE-2021-40145 - log back

CVE-2021-40145 edited at 26 Aug 2021 09:19:13
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ ** DISPUTED ** gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and testing purposes."
References
+ https://github.com/libgd/libgd/issues/700
+ https://github.com/libgd/libgd/pull/713
+ https://github.com/libgd/libgd/commit/e95059590fadaabd9aadc0c0489804d75a3c5d52
CVE-2021-40145 created at 26 Aug 2021 09:17:46
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes