CVE-2016-1903: Buffer Overflow
Fixed bug (Memory Read via gdImageRotateInterpolated Array Index Out of Bounds). (CVE-2016-1903)
Other sources
The gdImageRotateInterpolated function in ext/gd/libgd/gdinterpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgdcolor argument to the imagerotate function.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2016-1903?
CVE-2016-1903 is a vulnerability in PHP that allows remote attackers to obtain sensitive information or cause a denial of service.
How severe is CVE-2016-1903?
CVE-2016-1903 has a severity rating of 9.1, which is considered critical.
What is the affected software for CVE-2016-1903?
The affected software for CVE-2016-1903 includes PHP versions before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2.
How can I fix CVE-2016-1903?
To fix CVE-2016-1903, you should update your PHP installation to version 5.5.31, 5.6.17, or 7.0.2.
Where can I find more information about CVE-2016-1903?
You can find more information about CVE-2016-1903 on the PHP website and the Openwall OSS Security mailing list.