Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Fmunozso

#16224de 53,635
16.6CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2017-10390
7.5
2016-12-13
Gd · Gd Graphics Library · CVE-2016-9933
**Name of the Vulnerable Software and Affected Versions** GD Graphics Library versions prior to 2.2.2 PHP versions prior to 5.6.28 and 7.x prior to 7.0.13 **Description** The issue is related to a stack consumption vulnerability in the `gdImageFillToBorder` function. This vulnerability can be exploited by remote attackers to cause a denial of service, resulting in a segmentation violation. The exploitation occurs when a crafted `imagefilltoborder` call is made, triggering the use of a negative color value. **Recommendations** For GD Graphics Library versions prior to 2.2.2, update to version 2.2.2 or later. For PHP versions prior to 5.6.28, update to version 5.6.28 or later. For PHP 7.x versions prior to 7.0.13, update to version 7.0.13 or later.
PT-2016-6247
9.1
2016-05-30
Gd · Gd Graphics Library · CVE-2016-5116
**Name of the Vulnerable Software and Affected Versions** GD Graphics Library versions prior to 2.2.0 **Description** The issue allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service via a long name. This is due to a stack-based buffer under-read and application crash in the gd xbm.c file. **Recommendations** For versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue.