PT-2016-3376 · Gd+3 · Gd Graphics Library+3

Trylab

·

Publicado

2016-09-28

·

Atualizado

2019-03-07

·

CVE-2016-7568

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GD Graphics Library versions through 2.2.3 PHP versions through 7.0.11
Description The issue is caused by an integer overflow in the gdImageWebpCtx function, which can lead to a denial of service or possibly other impacts. This can be triggered by crafted imagewebp and imagedestroy calls, allowing remote attackers to exploit the weakness.
Recommendations For GD Graphics Library versions through 2.2.3, update to a version later than 2.2.3 to resolve the issue. For PHP versions through 7.0.11, update to a version later than 7.0.11 to resolve the issue. As a temporary workaround, consider restricting the use of the imagewebp and imagedestroy functions until a patch is available.

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02406
CVE-2016-7568
DSA-3693-1
MGASA-2016-0339
OPENSUSE-SU-2016_2606-1
OPENSUSE-SU-2016_2607-1
OPENSUSE-SU-2016_2772-1
OPENSUSE-SU-2016_2831-1
OPENSUSE-SU-2016_2837-1
SUSE-SU-2016:2668-1
SUSE-SU-2016:2683-1
SUSE-SU-2016:2683-2
SUSE-SU-2016:2766-1
USN-3117-1

Produtos afetados

Gd Graphics Library
Php
Suse
Ubuntu