CVE-2016-6214Out-of-bounds Read in Libgd

Severity
6.5MEDIUMNVD
EPSS
7.4%
top 8.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 14

Description

gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/libgd2< libgd2 2.2.2-29-g3c2b605-1 (bookworm)
NVDlibgd/libgd2.2.2
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3cgp-hvw6-ghr7: gd_tga2022-05-14
OSV
CVE-2016-6214: gd_tga2016-08-12
OSV
libgd2 vulnerabilities2016-08-10

📋Vendor Advisories

3
Ubuntu
GD library vulnerabilities2016-08-10
Red Hat
gd: Buffer over-read issue when parsing crafted TGA file2016-07-12
Debian
CVE-2016-6214: libgd2 - gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attac...2016

💬Community

2
Bugzilla
CVE-2016-6214 gd: Buffer over-read issue when parsing crafted TGA file [fedora-all]2016-07-14
Bugzilla
CVE-2016-6214 gd: Buffer over-read issue when parsing crafted TGA file2016-07-14