CVE-2016-6207

MEDIUM

GD Graphics Library <2.2.3 - DoS

Title source: llm

Description

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

Scores

CVSS v3 6.5
EPSS 0.0872
EPSS Percentile 92.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-119 CWE-190 CWE-787
Status draft

Affected Products (4)

libgd/libgd < 2.2.2
debian/debian_linux
opensuse/leap
php/php < 5.5.38

Timeline

Published Aug 12, 2016
Tracked Since Feb 18, 2026