CVE-2016-10166
Description
Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.
In plain language
AI Worth attentionlibgd before 2.2.4 can be crashed or potentially taken over by a malicious image, so small businesses using it should arrange an update.
Remote, unauthenticated integer underflow in libgd image-smoothing memory allocation can process crafted input with an invalid allocation size, causing denial of service or potential code execution.
What to do now
- Check whether your servers or applications include libgd and identify its installed version.
- Update libgd to version 2.2.4 or later through your operating system, application vendor, or deployment process.
- If an update must wait, stop accepting untrusted images in affected image-smoothing workflows and restrict public access to the application.
- Review application errors for image-processing crashes after applying the update.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-10166 and every CVE in our database. Create a free account — no credit card required.
Create Free Account