{"id":"CVE-2019-6978","details":"The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.","modified":"2026-05-15T12:03:56.007512188Z","published":"2019-01-28T08:29:00.607Z","related":["ALSA-2019:2722","ALSA-2020:4659","SUSE-SU-2019:0333-1","SUSE-SU-2019:0747-1","SUSE-SU-2019:0771-1","SUSE-SU-2019:13961-1","SUSE-SU-2022:1516-1","SUSE-SU-2022:1560-1","openSUSE-SU-2019:1148-1","openSUSE-SU-2024:10777-1","openSUSE-SU-2024:11012-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"14.04"},{"last_affected":"16.04"},{"last_affected":"18.04"},{"last_affected":"18.10"}],"source":"CPE_FIELD","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0"},{"last_affected":"9.0"}],"source":"CPE_FIELD","vendor_product":"debian:debian_linux"}]},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00025.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00031.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WRUPZVT2MWFUEMVGTRAGDOBHLNMGK5R/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEYUUOW75YD3DENIPYMO263E6NL2NFHI/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TTXSLRZI5BCQT3H5KALG3DHUWUMNPDX2/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2722"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/01/msg00028.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201903-18"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3900-1/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4384"},{"type":"FIX","url":"https://github.com/libgd/libgd/commit/553702980ae89c83f2d6e254d62cf82e204956d0"},{"type":"FIX","url":"https://github.com/libgd/libgd/issues/492"},{"type":"FIX","url":"https://github.com/php/php-src/commit/089f7c0bc28d399b0420aa6ef058e4c1c120b2ae"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}