CVE-2016-1903

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.

References

http://lists.opensuse.org/opensuse-updates/2016-01/msg00099.html

http://lists.opensuse.org/opensuse-updates/2016-02/msg00037.html

http://rhn.redhat.com/errata/RHSA-2016-2750.html

http://www.openwall.com/lists/oss-security/2016/01/14/8

http://www.php.net/ChangeLog-5.php

http://www.php.net/ChangeLog-7.php

http://www.securityfocus.com/bid/79916

http://www.securitytracker.com/id/1034608

http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.461720

http://www.ubuntu.com/usn/USN-2952-1

http://www.ubuntu.com/usn/USN-2952-2

https://bugs.php.net/bug.php?id=70976

https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05240731

Details

Source: MITRE

Published: 2016-01-19

Updated: 2018-01-05

Type: CWE-119

Risk Information

CVSS v2

Base Score: 6.4

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Impact Score: 4.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Impact Score: 5.2

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (12 total)

IDNameProductFamilySeverity
98873PHP 5.6.x < 5.6.17 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
98842PHP 7.x < 7.0.2 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
119973SUSE SLES12 Security Update : php5 (SUSE-SU-2016:0284-1)NessusSuSE Local Security Checks
critical
90825Ubuntu 15.10 : php5 regression (USN-2952-2)NessusUbuntu Local Security Checks
critical
90677Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : php5 vulnerabilities (USN-2952-1)NessusUbuntu Local Security Checks
critical
88680PHP 7.x < 7.0.2 Multiple VulnerabilitiesNessusCGI abuses
high
88679PHP prior to 5.5.x < 5.5.31 / 5.6.x < 5.6.17 Multiple VulnerabilitiesNessusCGI abuses
critical
88611openSUSE Security Update : php5 (openSUSE-2016-157)NessusSuSE Local Security Checks
critical
88567Slackware 14.0 / 14.1 / current : php (SSA:2016-034-04)NessusSlackware Local Security Checks
critical
88533openSUSE Security Update : php5 (openSUSE-2016-100)NessusSuSE Local Security Checks
critical
9063PHP 5.5.x < 5.5.31 / 5.6.x < 5.6.17 / 7.0.x < 7.0.2 Multiple VulnerabilitiesNessus Network MonitorWeb Servers
high
87974Amazon Linux AMI : php56 / php55 (ALAS-2016-640)NessusAmazon Linux Local Security Checks
critical