CVE-2016-10167

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-10167
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10167.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-10167
Downstream
Related
Published
2017-03-15T15:59:00Z
Modified
2025-09-30T02:10:06.071302Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

References

Affected packages

Git / github.com/libgd/libgd

Affected ranges

Type
GIT
Repo
https://github.com/libgd/libgd
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

GD_1_3_0
GD_1_4_0
GD_1_5_0
GD_1_6_0
GD_1_6_1
GD_1_6_2
GD_1_6_3
GD_1_7_0
GD_1_7_1
GD_1_7_2
GD_1_7_3
GD_1_8_0
GD_1_8_1
GD_1_8_3
GD_1_8_4
GD_2_0_0
GD_2_0_1
GD_2_0_10
GD_2_0_11
GD_2_0_12
GD_2_0_13
GD_2_0_14
GD_2_0_15
GD_2_0_17
GD_2_0_18
GD_2_0_19
GD_2_0_2
GD_2_0_20
GD_2_0_21
GD_2_0_22
GD_2_0_23
GD_2_0_24
GD_2_0_25
GD_2_0_26
GD_2_0_27
GD_2_0_28
GD_2_0_29
GD_2_0_3
GD_2_0_30
GD_2_0_31
GD_2_0_32
GD_2_0_33
GD_2_0_34RC1
GD_2_0_4
GD_2_0_5
GD_2_0_6
GD_2_0_7
GD_2_0_8
GD_2_0_9

gd-2.*

gd-2.1.0
gd-2.1.0-alpha1
gd-2.1.0-rc1
gd-2.1.0-rc2
gd-2.1.1
gd-2.2.0
gd-2.2.1

Database specific

{
    "vanir_signatures": [
        {
            "deprecated": false,
            "target": {
                "file": "src/gd_gd2.c"
            },
            "source": "https://github.com/libgd/libgd/commit/fe9ed49dafa993e3af96b6a5a589efeea9bfb36f",
            "signature_type": "Line",
            "id": "CVE-2016-10167-00cccb07",
            "signature_version": "v1",
            "digest": {
                "line_hashes": [
                    "194411151092001232974339546275188206885",
                    "267823361290543127515268673003405516669",
                    "171271300336810592618540495083476143259",
                    "71661422941037358524760434477336173087",
                    "213441941253899852367604743567420560542",
                    "216320710150188578254777252806342596233",
                    "179848356536284711233238296906354064310",
                    "294931990662525762394580523145401463678",
                    "48041632553446385702883507090134285843"
                ],
                "threshold": 0.9
            }
        },
        {
            "deprecated": false,
            "target": {
                "function": "gdImageCreateFromGd2Ctx",
                "file": "src/gd_gd2.c"
            },
            "source": "https://github.com/libgd/libgd/commit/fe9ed49dafa993e3af96b6a5a589efeea9bfb36f",
            "signature_type": "Function",
            "id": "CVE-2016-10167-8128f0b7",
            "signature_version": "v1",
            "digest": {
                "function_hash": "10047066907252219339000400664784805184",
                "length": 2491.0
            }
        }
    ]
}