Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10167

Опубликовано: 15 мар. 2017
Источник: debian
EPSS Низкий

Описание

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.1fixed7.1.1-1package
php7.0fixed7.0.15-1package
php5removedpackage
php5fixed5.6.30+dfsg-0+deb8u1jessiepackage
libgd2fixed2.2.4-1package

Примечания

  • PHP Bug: https://bugs.php.net/bug.php?id=73868

  • Fixed in PHP 7.1.1, 7.0.15, 5.6.30

  • https://github.com/libgd/libgd/commit/fe9ed49dafa993e3af96b6a5a589efeea9bfb36f

  • https://www.openwall.com/lists/oss-security/2017/01/26/1

EPSS

Процентиль: 76%
0.00975
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

CVSS3: 5.3
redhat
около 9 лет назад

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

CVSS3: 5.5
nvd
больше 8 лет назад

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

CVSS3: 5.5
github
больше 3 лет назад

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

fstec
больше 8 лет назад

Уязвимость графической библиотеки GD Graphics Library, позволяющая нарушителю оказать неопределенное воздействие

EPSS

Процентиль: 76%
0.00975
Низкий