VulnerabilityModified
CVE-2016-10168
Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.
HIGH 7.8EPSS 3.72%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 3.72% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- libgd/libgd
- Source
- security@debian.org
References
- http://libgd.github.io/release-2.2.4.htmlVendor Advisory
- http://www.debian.org/security/2017/dsa-3777
- http://www.openwall.com/lists/oss-security/2017/01/26/1Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/01/28/6Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/95869Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037659
- https://access.redhat.com/errata/RHSA-2017:3221
- https://access.redhat.com/errata/RHSA-2018:1296
- https://github.com/libgd/libgd/commit/69d2fd2c597ffc0c217de1238b9bf4d4bceba8e6Issue Tracking, Patch, Third Party Advisory
- https://github.com/libgd/libgd/issues/354Issue Tracking, Patch, Third Party Advisory
- http://libgd.github.io/release-2.2.4.htmlVendor Advisory
- http://www.debian.org/security/2017/dsa-3777
- http://www.openwall.com/lists/oss-security/2017/01/26/1Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/01/28/6Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/95869Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037659
- https://access.redhat.com/errata/RHSA-2017:3221
- https://access.redhat.com/errata/RHSA-2018:1296
- https://github.com/libgd/libgd/commit/69d2fd2c597ffc0c217de1238b9bf4d4bceba8e6Issue Tracking, Patch, Third Party Advisory
- https://github.com/libgd/libgd/issues/354Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.