Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6161

Опубликовано: 08 мая 2016
Источник: redhat
CVSS3: 5.9
CVSS2: 4.3

Описание

The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.

An out-of-bounds read flaw was found in gd. A maliciously crafted .gd2 file when converted to .gif could result in information disclosure from the process linking libgd.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gdWill not fix
Red Hat Enterprise Linux 5phpWill not fix
Red Hat Enterprise Linux 5php53Will not fix
Red Hat Enterprise Linux 5tetexNot affected
Red Hat Enterprise Linux 6gdWill not fix
Red Hat Enterprise Linux 6graphvizNot affected
Red Hat Enterprise Linux 6phpWill not fix
Red Hat Enterprise Linux 6texliveNot affected
Red Hat Enterprise Linux 7gdWill not fix
Red Hat Enterprise Linux 7phpWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1353550gd: Global out-of-bounds read when encoding gif from malformed gd2 input

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 9 лет назад

The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.

CVSS3: 6.5
nvd
больше 9 лет назад

The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.

CVSS3: 6.5
debian
больше 9 лет назад

The output function in gd_gif_out.c in the GD Graphics Library (aka li ...

suse-cvrf
больше 9 лет назад

Security update for gd

CVSS3: 6.5
github
больше 3 лет назад

The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.

5.9 Medium

CVSS3

4.3 Medium

CVSS2