4.3
CVSSv2

CVE-2016-10167

Published: 15/03/2017 Updated: 04/05/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) prior to 2.2.4 allows remote malicious users to cause a denial of service (application crash) via a crafted image file.

Vulnerable Product Search on Vulmon Subscribe to Product

libgd libgd

Vendor Advisories

The GD library could be made to crash or run programs if it processed a specially crafted image file ...
Synopsis Moderate: rh-php70-php security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-php70-php is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Synopsis Moderate: php security update Type/Severity Security Advisory: Moderate Topic An update for php is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which give ...
Multiple vulnerabilities have been discovered in libgd2, a library for programmatic graphics creation and manipulation, which may result in denial of service or potentially the execution of arbitrary code if a malformed file is processed For the stable distribution (jessie), these problems have been fixed in version 210-5+deb8u9 For the testing ...
Integer overflow in gd_ioc in the GD Graphics Library (aka libgd) before 224 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image(CVE-2016-10168) The object_common1 function in ext/standard/var_unserializerc in PHP before 5630, 70x before 7015, and 71x before ...
Integer overflow in gd_ioc in the GD Graphics Library (aka libgd) before 224 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image (CVE-2016-10168) In all versions of PHP 7, during the unserialization process, resizing the 'properties'; hash table of a serialized object ...
A null pointer dereference flaw was found in libgd An attacker could use a specially-crafted gd2 file to cause an application linked with libgd to crash, leading to denial of service ...
SecurityCenter has recently been discovered to contain several vulnerabilities Four issues in the SC code were discovered during internal testing by Barry Clark, and several third-party libraries were upgraded as part of our internal security process Note that the library vulnerabilities were not fully diagnosed so SecurityCenter is possibly impa ...