CVE-2016-6912

CRITICAL

Libgd < 2.2.3 - Double Free

Title source: rule

Description

Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.

Scores

CVSS v3 9.8
EPSS 0.0088
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status draft

Affected Products (1)

libgd/libgd < 2.2.3

Timeline

Published Jan 26, 2017
Tracked Since Feb 18, 2026