gd: security bump to version 2.2.4
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Thu, 19 Jan 2017 13:44:51 +0000 (10:44 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Thu, 19 Jan 2017 14:09:12 +0000 (15:09 +0100)
commit39885cc5b0c6ff175fe3a115231bc2428840e7b7
tree82cf3ed0a40d685f8d2602289f2cb462b8a43a89
parentd06e23e79a638107acf97884b9d468ae92c07c91
gd: security bump to version 2.2.4

Fixes:
CVE-2016-9317 - gdImageCreate() doesn't check for oversized images and
as such is prone to DoS vulnerabilities.
CVE-2016-6912 - double-free in gdImageWebPtr()
(without CVE):
Potential unsigned underflow in gd_interpolation.c
DOS vulnerability in gdImageCreateFromGd2Ctx()
Signed Integer Overflow gd_io.c

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/gd/gd.hash
package/gd/gd.mk