This site requires JavaScript to be enabled to function correctly, please enable it.
Summary:
CVE-2016-6911 gd, php: Missing check for OOB read in dynamicGetbuf()
Product:
[Other] Security Response
Reporter:
Adam Mariš <amaris>
Component:
vulnerability Assignee:
Red Hat Product Security <security-response-team>
Status:
CLOSED
WONTFIX
QA Contact:
Severity:
medium
Docs Contact:
Priority:
medium
Version:
unspecified CC:
abhgupta, databases-maint, dmcphers, fedora, hhorak, jialiu, jmlich83, jokerman, jorton, kseifried, lmeyer, mmccomas, mskalick, rcollet, sardella, tiwillia, trepik, varekova, webstack-team
Target Milestone:
--- Keywords:
Security
Target Release:
---
Hardware:
All
OS:
Linux
Whiteboard:
Fixed In Version:
Doc Type:
If docs needed, set a value
Doc Text:
A vulnerability was found in gd. The function dynamicGetbuf() failed to check for out of bounds reads. An attacker could create a crafted image that would lead to a crash or, potentially, information disclosure.
Story Points:
---
Clone Of:
Environment:
Last Closed:
2016-12-16 04:30:55 UTC
Type:
---
Regression:
---
Mount Type:
---
Documentation:
---
CRM:
Verified Versions:
Category:
---
oVirt Team:
---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team:
---
Target Upstream Version:
Embargoed:
Bug Depends On:
1388788 , 1388790
Bug Blocks:
1388796
Attachments: