Description
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-534-1 | libgd2 security update |
Debian DSA |
DSA-3619-1 | libgd2 security update |
EUVD |
EUVD-2016-6701 | Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image. |
Ubuntu USN |
USN-3030-1 | GD library vulnerabilities |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T01:15:09.075Z
Reserved: 2016-06-23T00:00:00.000Z
Link: CVE-2016-5766
No data.
Status : Deferred
Published: 2016-08-07T10:59:13.663
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-5766
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN