CVE-2016-5766: Integer Overflow
Integer overflow in the gd2GetHeader function in gdgd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.
Other sources
Fixed bug (Integer Overflow in gd2GetHeader() resulting in heap overflow). (CVE-2016-5766)
— PHP
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5766?
CVE-2016-5766 is classified as a high severity vulnerability due to the potential for remote denial of service attacks and application crashes.
How do I fix CVE-2016-5766?
To fix CVE-2016-5766, update the GD Graphics Library to version 2.2.3 or later and ensure PHP is upgraded to 5.5.37, 5.6.23, or 7.0.8 or higher.
What systems are affected by CVE-2016-5766?
CVE-2016-5766 affects versions of the GD Graphics Library prior to 2.2.3 and vulnerable versions of PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8.
What type of attack can CVE-2016-5766 facilitate?
CVE-2016-5766 can facilitate remote attacks that result in a denial of service through heap-based buffer overflow vulnerabilities.
Is CVE-2016-5766 present in all versions of PHP?
No, CVE-2016-5766 is not present in all versions of PHP; it affects specific versions prior to their respective security patches.