CVE-2016-6912 — Double Free in Libgd
Severity
9.8CRITICALNVD
EPSS
0.9%
top 24.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26
Latest updateMay 2
Description
Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages1 packages
Patches
🔴Vulnerability Details
4GHSA▶
GHSA-wmff-45hx-q83q: Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2↗2022-05-17
CVEList▶
CVE-2016-6912: Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2↗2017-01-26
OSV▶
CVE-2016-6912: Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2↗2017-01-26
📋Vendor Advisories
3📄Research Papers
1arXiv▶
Poster: Machine Learning for Vulnerability Detection as Target Oracle in Automated Fuzz Driver Generation↗2025-05-02