CVE-2016-9933
Summary
| CVE | CVE-2016-9933 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-01-04 20:59:00 UTC |
| Updated | 2018-05-04 01:29:00 UTC |
| Description | Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefilltoborder call that triggers use of a negative color value. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Libgd | Libgd | 2.2.1 | All | All | All |
| Application | Libgd | Libgd | 2.2.1 | All | All | All |
| Application | Php | Php | 7.0.0 | All | All | All |
| Application | Php | Php | 7.0.1 | All | All | All |
| Application | Php | Php | 7.0.10 | All | All | All |
| Application | Php | Php | 7.0.11 | All | All | All |
| Application | Php | Php | 7.0.2 | All | All | All |
| Application | Php | Php | 7.0.3 | All | All | All |
| Application | Php | Php | 7.0.4 | All | All | All |
| Application | Php | Php | 7.0.5 | All | All | All |
| Application | Php | Php | 7.0.6 | All | All | All |
| Application | Php | Php | 7.0.7 | All | All | All |
| Application | Php | Php | 7.0.8 | All | All | All |
| Application | Php | Php | 7.0.9 | All | All | All |
| Application | Php | Php | All | All | All | All |
| Application | Php | Php | 7.0.0 | All | All | All |
| Application | Php | Php | 7.0.1 | All | All | All |
| Application | Php | Php | 7.0.10 | All | All | All |
| Application | Php | Php | 7.0.11 | All | All | All |
| Application | Php | Php | 7.0.2 | All | All | All |
| Application | Php | Php | 7.0.3 | All | All | All |
| Application | Php | Php | 7.0.4 | All | All | All |
| Application | Php | Php | 7.0.5 | All | All | All |
| Application | Php | Php | 7.0.6 | All | All | All |
| Application | Php | Php | 7.0.7 | All | All | All |
| Application | Php | Php | 7.0.8 | All | All | All |
| Application | Php | Php | 7.0.9 | All | All | All |
| Application | Php | Php | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| openSUSE-SU-2017:0081-1: moderate: Security update for php5 | SUSE | lists.opensuse.org | |
| gdImageFillToBorder stack-overflow when invalid color is used · Issue #215 · libgd/libgd · GitHub | CONFIRM | github.com | Vendor Advisory |
| openSUSE-SU-2016:3239-1: moderate: Security update for php5 | SUSE | lists.opensuse.org | |
| PHP :: Sec Bug #72696 :: imagefilltoborder stackoverflow on truecolor images | CONFIRM | bugs.php.net | Vendor Advisory |
| PHP 'src/gd.c' Denial of Service Vulnerability | BID | www.securityfocus.com | |
| fix #215 gdImageFillToBorder stack-overflow when invalid color is used · libgd/libgd@77f619d · GitHub | CONFIRM | github.com | Patch, Vendor Advisory |
| openSUSE-SU-2017:0061-1: moderate: Security update for php7 | SUSE | lists.opensuse.org | |
| Fix #72696: imagefilltoborder stackoverflow on truecolor images · php/php-src@863d37e · GitHub | CONFIRM | github.com | Vendor Advisory |
| Debian -- Security Information -- DSA-3751-1 libgd2 | DEBIAN | www.debian.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| openSUSE-SU-2016:3228-1: moderate: Security update for gd | SUSE | lists.opensuse.org | |
| openSUSE-SU-2017:0006-1: moderate: Security update for gd | SUSE | lists.opensuse.org | |
| oss-security - CVE assignment for PHP 5.6.28, 5.6.29, 7.0.13, 7.0.14 and 7.1.0 | MLIST | www.openwall.com | Third Party Advisory |
| PHP: PHP 7 ChangeLog | CONFIRM | www.php.net | Release Notes, Vendor Advisory |
| PHP: PHP 5 ChangeLog | CONFIRM | www.php.net | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.