Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7568

Опубликовано: 28 сент. 2016
Источник: debian
EPSS Низкий

Описание

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libgd2fixed2.2.3-87-gd0fec80-1package
libgd2not-affectedwheezypackage
php7.0fixed7.0.12-1package
php5removedpackage
php5fixed5.6.27+dfsg-0+deb8u1jessiepackage

Примечания

  • libgd bug: https://github.com/libgd/libgd/issues/308

  • Fixed by: https://github.com/libgd/libgd/commit/2806adfdc27a94d333199345394d7c302952b95f

  • PHP Bug: https://bugs.php.net/bug.php?id=73003

  • https://github.com/php/php-src/commit/c18263e0e0769faee96a5d0ee04b750c442783c6

EPSS

Процентиль: 76%
0.01023
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 7.1
redhat
почти 9 лет назад

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 9.8
nvd
больше 8 лет назад

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 9.8
github
около 3 лет назад

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость функции gdimagewebpctx графической библиотеки GD Graphics Library, интерпретатора языка программирования PHP , позволяющая нарушителю вызвать отказ в обслуживании или, возможно, оказать другое воздействие

EPSS

Процентиль: 76%
0.01023
Низкий