Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10167

Опубликовано: 16 авг. 2016
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

A null pointer dereference flaw was found in libgd. An attacker could use a specially-crafted .gd2 file to cause an application linked with libgd to crash, leading to denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gdWill not fix
Red Hat Enterprise Linux 5libwmfWill not fix
Red Hat Enterprise Linux 5phpWill not fix
Red Hat Enterprise Linux 5php53Will not fix
Red Hat Enterprise Linux 6gdWill not fix
Red Hat Enterprise Linux 6libwmfWill not fix
Red Hat Enterprise Linux 6phpWill not fix
Red Hat Enterprise Linux 7gdWill not fix
Red Hat Enterprise Linux 7libwmfWill not fix
Red Hat Software Collectionsrh-php56-phpWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1418984gd: DoS vulnerability in gdImageCreateFromGd2Ctx()

EPSS

Процентиль: 76%
0.00975
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

CVSS3: 5.5
nvd
больше 8 лет назад

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

CVSS3: 5.5
debian
больше 8 лет назад

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Li ...

CVSS3: 5.5
github
больше 3 лет назад

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

fstec
больше 8 лет назад

Уязвимость графической библиотеки GD Graphics Library, позволяющая нарушителю оказать неопределенное воздействие

EPSS

Процентиль: 76%
0.00975
Низкий

5.3 Medium

CVSS3