High severity7.5NVD Advisory· Published May 22, 2016· Updated Jun 17, 2026
CVE-2015-8877
CVE-2015-8877
Description
The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses inconsistent allocate and free approaches, which allows remote attackers to cause a denial of service (memory consumption) via a crafted call, as demonstrated by a call to the PHP imagescale function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- osv-coords10 versionspkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012pkg:rpm/suse/imap&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1
< 2007e_suse-19.1+ 9 more
- (no CPE)range: < 2007e_suse-19.1
- (no CPE)range: < 2007e_suse-19.1
- (no CPE)range: < 2007e_suse-19.1
- (no CPE)range: < 2007e_suse-19.1
- (no CPE)range: < 2007e_suse-19.1
- (no CPE)range: < 2007e_suse-19.1
- (no CPE)range: < 2007e_suse-19.1
- (no CPE)range: < 5.5.14-64.5
- (no CPE)range: < 5.5.14-64.5
- (no CPE)range: < 5.5.14-64.5
Patches
Vulnerability mechanics
References
7News mentions
0No linked articles in our index yet.