CVE-2016-6912Double Free in Libgd

Severity
9.8CRITICALNVD
EPSS
0.9%
top 24.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26
Latest updateMay 2

Description

Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDlibgd/libgd2.2.3

Patches

🔴Vulnerability Details

4
GHSA
GHSA-wmff-45hx-q83q: Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 22022-05-17
OSV
libgd2 vulnerabilities2017-02-28
CVEList
CVE-2016-6912: Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 22017-01-26
OSV
CVE-2016-6912: Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 22017-01-26

📋Vendor Advisories

3
Ubuntu
GD library vulnerabilities2017-02-28
Red Hat
php: Double free in gdImageWebpPtr()2016-08-16
Debian
CVE-2016-6912: libgd2 - Double free vulnerability in the gdImageWebPtr function in the GD Graphics Libra...2016

📄Research Papers

1
arXiv
Poster: Machine Learning for Vulnerability Detection as Target Oracle in Automated Fuzz Driver Generation2025-05-02

💬Community

3
Bugzilla
CVE-2016-10166 CVE-2016-10167 CVE-2016-10168 CVE-2016-6912 php: various flaws [fedora-all]2017-02-03
Bugzilla
CVE-2016-10166 CVE-2016-10167 CVE-2016-10168 CVE-2016-6912 CVE-2016-9317 libwmf: various flaws [fedora-all]2017-02-03
Bugzilla
CVE-2016-6912 gd, php: Double free in gdImageWebpPtr()2017-01-31