Stack based buffer overflow was found in dynamicGetbuf when passing negative `rlen` as size to memcpy(). PHP bug: https://bugs.php.net/bug.php?id=73280 GD patch: https://github.com/libgd/libgd/commit/53110871935244816bbb9d131da0bccff734bfe9 PHP patch: https://git.php.net/?p=php-src.git;a=commit;h=cc08cbc84d46933c1e9e0149633f1ed5d19e45e9 CVE assignment: http://www.openwall.com/lists/oss-security/2016/10/15/6
Created gd tracking bugs for this issue: Affects: fedora-all [bug 1391077]
Created php tracking bugs for this issue: Affects: fedora-all [bug 1391076]