Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10168

Опубликовано: 17 дек. 2016
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

An integer overflow flaw, leading to a heap-based buffer overflow was found in the way libgd read some specially-crafted gd2 files. A remote attacker could use this flaw to crash an application compiled with libgd or in certain cases execute arbitrary code with the privileges of the user running that application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gdWill not fix
Red Hat Enterprise Linux 5libwmfWill not fix
Red Hat Enterprise Linux 5phpWill not fix
Red Hat Enterprise Linux 5php53Will not fix
Red Hat Enterprise Linux 6gdWill not fix
Red Hat Enterprise Linux 6libwmfWill not fix
Red Hat Enterprise Linux 6phpWill not fix
Red Hat Enterprise Linux 7gdWill not fix
Red Hat Enterprise Linux 7libwmfWill not fix
Red Hat Software Collectionsrh-php56-phpWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190

EPSS

Процентиль: 70%
0.00655
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

CVSS3: 7.8
nvd
больше 8 лет назад

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

CVSS3: 7.8
debian
больше 8 лет назад

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) bef ...

CVSS3: 7.8
github
больше 3 лет назад

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

fstec
больше 8 лет назад

Уязвимость графической библиотеки GD Graphics Library, позволяющая нарушителю оказать неопределенное воздействие

EPSS

Процентиль: 70%
0.00655
Низкий

6.3 Medium

CVSS3