CVE-2016-3074: Buffer Overflow
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.
Other sources
Fixed bug (libgd: signedness vulnerability). (CVE-2016-3074)
— PHP
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3074?
CVE-2016-3074 has been classified with a high severity level due to the potential for remote code execution and denial of service.
How do I fix CVE-2016-3074?
To fix CVE-2016-3074, update the GD Graphics Library to version 2.1.1 or later, and ensure your PHP version is updated to at least 7.0.6.
What systems are affected by CVE-2016-3074?
CVE-2016-3074 affects GD Graphics Library version 2.1.1, as well as various PHP versions prior to 7.0.6, and multiple Linux distributions including Debian, Fedora, and Ubuntu.
Can CVE-2016-3074 lead to remote exploitation?
Yes, CVE-2016-3074 can lead to remote exploitation through crafted compressed gd2 data, which may result in a heap-based buffer overflow.
Is there a patch available for CVE-2016-3074?
Yes, a patch is available that addresses the vulnerability specifically in GD Graphics Library and its dependent software.