CVE-2016-6207: Integer Overflow
Integer overflow in the gdContributionsAlloc function in gdinterpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.
Other sources
Fixed bug (Integer overflow error within gdContributionsAlloc()). (CVE-2016-6207)
— PHP
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6207?
CVE-2016-6207 is classified as a medium severity vulnerability due to the potential for denial of service.
How do I fix CVE-2016-6207?
To fix CVE-2016-6207, upgrade GD Graphics Library to version 2.2.3 or later.
Which versions of PHP are affected by CVE-2016-6207?
CVE-2016-6207 affects PHP versions prior to 7.0.9, including the ranges 5.5.0 to 5.5.38 and 5.6.0 to 5.6.24.
What impact does CVE-2016-6207 have on systems?
CVE-2016-6207 can lead to denial of service due to out-of-bounds memory writes or memory consumption.
Which software is vulnerable to CVE-2016-6207?
CVE-2016-6207 affects versions of libgd up to 2.2.2, as well as certain PHP versions and Debian and openSUSE distributions.