CVE-2016-10166: Integer Overflow
An unsigned integer overflow vulnerability was found in gdContributionsAlloc function.
Upstream patch:
https://github.com/libgd/libgd/commit/60bfb401ad5a4a8ae995dcd36372fe15c71e1a35
CVE assignment:
http://www.openwall.com/lists/oss-security/2017/01/28/6
Other sources
Fixed bug (efree() on uninitialized Heap data in imagescale leads to use-after-free). (CVE-2016-10166)
— PHP
Integer underflow in the gdContributionsAlloc function in gdinterpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2016-10166?
CVE-2016-10166 has been classified with a moderate severity due to the potential for an unsigned integer overflow leading to exploitation.
How do I fix CVE-2016-10166?
To fix CVE-2016-10166, upgrade to versions 0:7.1.30-1.el7, 0:7.2.24-1.el7 for rh-php71-php and rh-php72-php, or update to gd version 2.2.4.
Which software is affected by CVE-2016-10166?
CVE-2016-10166 affects rh-php71-php, rh-php72-php, PHP versions 5.6.40 and 7.1.26, and gd versions up to 2.2.3.
What is the impact of CVE-2016-10166?
The impact of CVE-2016-10166 includes potential Denial of Service or remote code execution due to the integer overflow vulnerability.
When was CVE-2016-10166 published?
CVE-2016-10166 was published in January 2017 as part of the ongoing efforts to address vulnerabilities in the libgd library.