The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
[
{
"target": {
"file": "src/gd_gd2.c"
},
"id": "CVE-2016-10167-00cccb07",
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/libgd/libgd/commit/fe9ed49dafa993e3af96b6a5a589efeea9bfb36f",
"digest": {
"line_hashes": [
"194411151092001232974339546275188206885",
"267823361290543127515268673003405516669",
"171271300336810592618540495083476143259",
"71661422941037358524760434477336173087",
"213441941253899852367604743567420560542",
"216320710150188578254777252806342596233",
"179848356536284711233238296906354064310",
"294931990662525762394580523145401463678",
"48041632553446385702883507090134285843"
],
"threshold": 0.9
}
},
{
"target": {
"function": "gdImageCreateFromGd2Ctx",
"file": "src/gd_gd2.c"
},
"id": "CVE-2016-10167-8128f0b7",
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/libgd/libgd/commit/fe9ed49dafa993e3af96b6a5a589efeea9bfb36f",
"digest": {
"function_hash": "10047066907252219339000400664784805184",
"length": 2491.0
}
}
]