Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10168

Опубликовано: 15 мар. 2017
Источник: debian

Описание

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.1fixed7.1.1-1package
php7.0fixed7.0.15-1package
php5removedpackage
php5fixed5.6.30+dfsg-0+deb8u1jessiepackage
libgd2fixed2.2.4-1package

Примечания

  • PHP Bug: https://bugs.php.net/bug.php?id=73869

  • Fixed in PHP 7.1.1, 7.0.15, 5.6.30

  • https://github.com/libgd/libgd/commit/69d2fd2c597ffc0c217de1238b9bf4d4bceba8e6

  • https://www.openwall.com/lists/oss-security/2017/01/26/1

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

CVSS3: 6.3
redhat
почти 9 лет назад

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

CVSS3: 7.8
nvd
больше 8 лет назад

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

CVSS3: 7.8
github
больше 3 лет назад

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

fstec
больше 8 лет назад

Уязвимость графической библиотеки GD Graphics Library, позволяющая нарушителю оказать неопределенное воздействие