CVE-2016-10166
moderate-risk
Published 2017-03-15
Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.
Do I need to act?
~
8.3% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 60bfb401ad5a4a8ae995dcd36372fe15c71e1a35
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (16)
Release Notes
http://libgd.github.io/release-2.2.4.html
Third Party Advisory
http://www.securityfocus.com/bid/95869
Release Notes
http://libgd.github.io/release-2.2.4.html
Third Party Advisory
http://www.securityfocus.com/bid/95869
47
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
10/34 · Low
Exposure
5/34 · Minimal