CVE-2016-10167: Input Validation
Fixed bug (DOS vulnerability in gdImageCreateFromGd2Ctx()). (CVE-2016-10167)
Other sources
Possible DoS vulnerability in gdImageCreateFromGd2Ctx() was found.
Upstream patch:
https://github.com/libgd/libgd/commit/fe9ed49dafa993e3af96b6a5a589efeea9bfb36f
PHP bug:
https://bugs.php.net/bug.php?id=73868
CVE assignment:
http://www.openwall.com/lists/oss-security/2017/01/28/6
— Red Hat
The gdImageCreateFromGd2Ctx function in gdgd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10167?
CVE-2016-10167 is categorized as a denial of service vulnerability that can cause application crashes.
How do I fix CVE-2016-10167?
To fix CVE-2016-10167, you should upgrade to GD Graphics Library version 2.2.4 or higher.
Which versions of the GD Graphics Library are affected by CVE-2016-10167?
CVE-2016-10167 affects GD Graphics Library versions before 2.2.4.
What applications are impacted by CVE-2016-10167?
Applications using vulnerable versions of the GD Graphics Library, including those bundled with PHP, are impacted by CVE-2016-10167.
Can CVE-2016-10167 be exploited remotely?
Yes, CVE-2016-10167 can be exploited by remote attackers through crafted image files.