CVE-2016-9317: Input Validation
Published Jan 26, 2017
·Updated
The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image.
Affected Software
1 affected component
Libgd Libgd<=2.2.3
Remediation
Patch Available
Event History
Jan 26, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 12, 58332
Event
11:06 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-9317?
CVE-2016-9317 has a severity rating that indicates it can lead to denial of service due to a system hang.
2
How do I fix CVE-2016-9317?
To fix CVE-2016-9317, upgrade your GD Graphics Library to version 2.2.4 or later.
3
Who is affected by CVE-2016-9317?
CVE-2016-9317 affects all versions of the GD Graphics Library prior to version 2.2.4.
4
What are the potential impacts of CVE-2016-9317?
The potential impacts of CVE-2016-9317 include remote denial of service attacks that can cause system hangs.
5
Can CVE-2016-9317 be exploited remotely?
Yes, CVE-2016-9317 can be exploited remotely by attackers sending oversized images to the affected library.