← Back

CVE-2016-8670

nvd nist
Published: Jan 4, 2017Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted imagecreatefromstring call.

Affected (1)

Products: Libgd: Libgd
1 product
Libgd
Configuration A
1 vulnerable · 14 platform
Vulnerable SoftwareAffected Versions
Up to 2.2.3
Running on/withPlatform Versions
Php
Php
Up to 5.6.27
Php
Php
Version 7.0.0
Php
Php
Version 7.0.10
Php
Php
Version 7.0.11
Php
Php
Version 7.0.12
Php
Php
Version 7.0.1
Php
Php
Version 7.0.2
Php
Php
Version 7.0.3
Php
Php
Version 7.0.4
Php
Php
Version 7.0.5
Php
Php
Version 7.0.6
Php
Php
Version 7.0.7
Php
Php
Version 7.0.8
Php
Php
Version 7.0.9

References (16)

Source: security@debian.org
Third Party Advisory
Source: security@debian.org
Release NotesVendor Advisory
Source: security@debian.org
Release NotesVendor Advisory
Source: security@debian.org
Source: security@debian.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.