CVE-2016-6161

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.

References

http://lists.opensuse.org/opensuse-updates/2016-08/msg00086.html

http://lists.opensuse.org/opensuse-updates/2016-09/msg00078.html

http://www.debian.org/security/2016/dsa-3619

http://www.openwall.com/lists/oss-security/2016/07/05/6

http://www.openwall.com/lists/oss-security/2016/07/05/7

http://www.ubuntu.com/usn/USN-3030-1

https://github.com/libgd/libgd/issues/209

Details

Source: MITRE

Published: 2016-08-12

Updated: 2018-10-30

Type: CWE-125

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 2.8

Severity: MEDIUM

Tenable Plugins

View all (17 total)

IDNameProductFamilySeverity
135626EulerOS Virtualization 3.0.2.2 : gd (EulerOS-SA-2020-1464)NessusHuawei Local Security Checks
high
132300EulerOS 2.0 SP3 : gd (EulerOS-SA-2019-2583)NessusHuawei Local Security Checks
critical
131801EulerOS 2.0 SP5 : gd (EulerOS-SA-2019-2527)NessusHuawei Local Security Checks
medium
131674EulerOS 2.0 SP2 : gd (EulerOS-SA-2019-2521)NessusHuawei Local Security Checks
critical
119981SUSE SLES12 Security Update : php7 (SUSE-SU-2016:2460-1)NessusSuSE Local Security Checks
critical
119979SUSE SLES12 Security Update : php5 (SUSE-SU-2016:2408-1)NessusSuSE Local Security Checks
critical
94923F5 Networks BIG-IP : libgd vulnerability (K71581599)NessusF5 Networks Local Security Checks
medium
93872Fedora 23 : gd (2016-0de0e0ee0c)NessusFedora Local Security Checks
medium
93856openSUSE Security Update : php5 (openSUSE-2016-1156)NessusSuSE Local Security Checks
critical
93701openSUSE Security Update : gd (openSUSE-2016-1108)NessusSuSE Local Security Checks
critical
93506SUSE SLED12 / SLES12 Security Update : gd (SUSE-SU-2016:2303-1)NessusSuSE Local Security Checks
critical
93505SUSE SLES11 Security Update : gd (SUSE-SU-2016:2302-1)NessusSuSE Local Security Checks
medium
93063openSUSE Security Update : gd (openSUSE-2016-1003)NessusSuSE Local Security Checks
high
92982openSUSE Security Update : php5 (openSUSE-2016-985)NessusSuSE Local Security Checks
critical
92570Debian DLA-563-1 : libgd2 security updateNessusDebian Local Security Checks
medium
92327Debian DSA-3619-1 : libgd2 - security updateNessusDebian Local Security Checks
critical
92011Ubuntu 12.04 LTS / 14.04 LTS / 15.10 / 16.04 LTS : libgd2 vulnerabilities (USN-3030-1)NessusUbuntu Local Security Checks
critical