← All CVEs

CVE-2016-3074

critical · 9.8

Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.

9.8
CVSS
37.0%
EPSS (exploit prob.)
98th
EPSS percentile
2016-04-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-681

Affected products

VendorProductAffected versions
libgdlibgd2.1.1
debiandebian_linux7.0
debiandebian_linux8.0
fedoraprojectfedora23
fedoraprojectfedora24
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.10
canonicalubuntu_linux16.04
opensuseopensuse13.2
phpphp>= 5.5.0, < 5.5.35
phpphp>= 5.6.0, < 5.6.21
phpphp>= 7.0.0, < 7.0.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-3074