« List of all CVEs

CVE-2016-8670

Published: 1/4/2017 Last updated: 8/6/2024 Reserved: 10/15/2016

Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted imagecreatefromstring call.

CNA assigner: debian (79363d38-fa19-49d1-9214-5f28da3f3ac5) Requested by: n/a

Opam packages affected (1)

conf-gd

Products affected (1)

Product Vendor Version
n/a n/a 1.0

References (32)