CVE-2016-9933
Last modified
CVE-2016-9933 is a vulnerability of currently unknown severity. Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefilltoborder call that triggers use of a negative color value.. EPSS estimates a 6.87% chance of exploitation in the next 30 days.
Description
Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefilltoborder call that triggers use of a negative color value.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libgd | Libgd | 2.2.1 |
References
- http://www.openwall.com/lists/oss-security/2016/12/12/2Third Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://www.php.net/ChangeLog-7.phpRelease Notes, Vendor Advisory
- https://bugs.php.net/bug.php?id=72696Vendor Advisory
- https://github.com/libgd/libgd/commit/77f619d48259383628c3ec4654b1ad578e9eb40ePatch, Vendor Advisory
- https://github.com/libgd/libgd/issues/215Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/12/12/2Third Party Advisory
- http://www.php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://www.php.net/ChangeLog-7.phpRelease Notes, Vendor Advisory
- https://bugs.php.net/bug.php?id=72696Vendor Advisory
- https://github.com/libgd/libgd/commit/77f619d48259383628c3ec4654b1ad578e9eb40ePatch, Vendor Advisory
- https://github.com/libgd/libgd/issues/215Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9933?
How severe is CVE-2016-9933?
How do I fix CVE-2016-9933?
Are you affected by CVE-2016-9933?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
