CVE-2016-6906: Medium severity libgd vulnerability
Published Mar 15, 2017
·Updated
The readimagetga function in gdtga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.
Affected Software
1 affected component
Libgd Libgd<=2.2.3
Remediation
Event History
Mar 15, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6906?
CVE-2016-6906 is classified as a denial of service vulnerability that can lead to crashes or service disruption.
2
How do I fix CVE-2016-6906?
To fix CVE-2016-6906, upgrade your GD Graphics Library (libgd) to version 2.2.4 or later.
3
What causes CVE-2016-6906?
CVE-2016-6906 is caused by an out-of-bounds read in the read_image_tga function when processing crafted TGA files.
4
Which versions of libgd are affected by CVE-2016-6906?
CVE-2016-6906 affects libgd versions earlier than 2.2.4.
5
Can I mitigate CVE-2016-6906 without upgrading libgd?
There are no known mitigations for CVE-2016-6906 that do not involve upgrading to a patched version of libgd.