PT-2016-3376 · Gd+3 · Gd Graphics Library+3
Trylab
·
Publicado
2016-09-28
·
Atualizado
2019-03-07
·
CVE-2016-7568
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GD Graphics Library versions through 2.2.3
PHP versions through 7.0.11
Description
The issue is caused by an integer overflow in the
gdImageWebpCtx function, which can lead to a denial of service or possibly other impacts. This can be triggered by crafted imagewebp and imagedestroy calls, allowing remote attackers to exploit the weakness.Recommendations
For GD Graphics Library versions through 2.2.3, update to a version later than 2.2.3 to resolve the issue.
For PHP versions through 7.0.11, update to a version later than 7.0.11 to resolve the issue.
As a temporary workaround, consider restricting the use of the
imagewebp and imagedestroy functions until a patch is available.Correção
DoS
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gd Graphics Library
Php
Suse
Ubuntu