CVE-2016-3074

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 26 Apr 2016, 14:00
Last modified:05 Aug 2024, 23:40

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
60.49% CRITICAL
60% probability +5.79%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

26 Apr 2016, 14:00
Published
Vulnerability first disclosed
05 Aug 2024, 23:40
Last Modified
Vulnerability information updated

Description

Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 60.49% Percentile: 98%

Techniques & Countermeasures

  • CWE-681Incorrect Conversion between Numeric Types

    When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.10 | 16.04

  • debiandebian_linux

    7.0 | 8.0

  • fedoraprojectfedora

    23 | 24

  • libgdlibgd

    2.1.1

  • opensuseopensuse

    13.2

  • UnknownPHP

    ≥ 5.5.0, < 5.5.35 | ≥ 5.6.0, < 5.6.21 | ≥ 7.0.0, < 7.0.6

References (18)