Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6207

Опубликовано: 07 июл. 2016
Источник: redhat
CVSS3: 6.2
CVSS2: 4.3
EPSS Низкий

Описание

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gdNot affected
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6gdNot affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7gdNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat OpenShift Enterprise 2gdNot affected
Red Hat Software Collectionsphp54-phpNot affected
Red Hat Software Collectionsphp55-phpWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1359800php,gd: Integer overflow error within _gdContributionsAlloc()

EPSS

Процентиль: 92%
0.08715
Низкий

6.2 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 9 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
nvd
почти 9 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
debian
почти 9 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpola ...

CVSS3: 6.5
github
около 3 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

suse-cvrf
почти 9 лет назад

Security update for gd

EPSS

Процентиль: 92%
0.08715
Низкий

6.2 Medium

CVSS3

4.3 Medium

CVSS2