PT-2016-3376 · Gd+3 · Gd Graphics Library+3
Trylab
·
Published
2016-09-28
·
Updated
2019-03-07
·
CVE-2016-7568
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GD Graphics Library versions through 2.2.3
PHP versions through 7.0.11
Description
The issue is caused by an integer overflow in the
gdImageWebpCtx function, which can lead to a denial of service or possibly other impacts. This can be triggered by crafted imagewebp and imagedestroy calls, allowing remote attackers to exploit the weakness.Recommendations
For GD Graphics Library versions through 2.2.3, update to a version later than 2.2.3 to resolve the issue.
For PHP versions through 7.0.11, update to a version later than 7.0.11 to resolve the issue.
As a temporary workaround, consider restricting the use of the
imagewebp and imagedestroy functions until a patch is available.Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gd Graphics Library
Php
Suse
Ubuntu