CVE-2016-9317Improper Input Validation in Libgd

Severity
5.5MEDIUMNVD
OSV9.8
EPSS
1.1%
top 22.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26
Latest updateMay 17

Description

The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

NVDlibgd/libgd2.2.3

Patches

🔴Vulnerability Details

4
GHSA
GHSA-7pf6-3qr6-mjfr: The gdImageCreate function in the GD Graphics Library (aka libgd) before 22022-05-17
OSV
libgd2 vulnerabilities2017-02-28
CVEList
CVE-2016-9317: The gdImageCreate function in the GD Graphics Library (aka libgd) before 22017-01-26
OSV
CVE-2016-9317: The gdImageCreate function in the GD Graphics Library (aka libgd) before 22017-01-26

📋Vendor Advisories

3
Ubuntu
GD library vulnerabilities2017-02-28
Red Hat
gd: Missing check for oversized images in gdImageCreate()2016-11-12
Debian
CVE-2016-9317: libgd2 - The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 a...2016

💬Community

2
Bugzilla
CVE-2016-10166 CVE-2016-10167 CVE-2016-10168 CVE-2016-6912 CVE-2016-9317 libwmf: various flaws [fedora-all]2017-02-03
Bugzilla
CVE-2016-9317 gd: Missing check for oversized images in gdImageCreate()2017-01-31