CVE-2016-5116: Buffer Overflow
gdxbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5116?
CVE-2016-5116 has been classified as a moderate severity vulnerability due to its potential to cause denial of service and information disclosure.
How do I fix CVE-2016-5116?
To fix CVE-2016-5116, update the GD Graphics Library to version 2.2.0 or later.
What software is affected by CVE-2016-5116?
CVE-2016-5116 affects versions of the GD Graphics Library prior to 2.2.0, particularly when used with certain versions of PHP 5.5.x.
What type of attack can be conducted using CVE-2016-5116?
CVE-2016-5116 allows attackers to perform a denial of service attack or potentially obtain sensitive information by exploiting a buffer under-read.
Are there any specific PHP versions that are vulnerable to CVE-2016-5116?
CVE-2016-5116 is particularly relevant for custom configurations of PHP 5.5.x, where the GD library is used.