Red Hat Bugzilla – Bug 1418983
CVE-2016-10166 gd: Unsigned integer overflow _gdContributionsAlloc
Last modified: 2018-03-31 23:02:15 EDT
An unsigned integer overflow vulnerability was found in _gdContributionsAlloc function. Upstream patch: https://github.com/libgd/libgd/commit/60bfb401ad5a4a8ae995dcd36372fe15c71e1a35 CVE assignment: http://www.openwall.com/lists/oss-security/2017/01/28/6
Created php tracking bugs for this issue: Affects: fedora-all [bug 1418991]
Created libwmf tracking bugs for this issue: Affects: fedora-all [bug 1418992]
Analysis: The code affects the _gdContributionsAlloc() function, which first appeared in gd-2.2.5. Red Hat Enterprise Linux 5, 6 and 7 does not ship with this gd version (or higher) either in an independent package or embedded with PHP, hence they are not affected.