Critical severity9.8NVD Advisory· Published Jan 4, 2017· Updated Jun 17, 2026
CVE-2016-8670
CVE-2016-8670
Description
Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted imagecreatefromstring call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- Range: <=2.2.3
- osv-coords15 versionspkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1
< 2.1.0-17.1+ 14 more
- (no CPE)range: < 2.1.0-17.1
- (no CPE)range: < 2.0.36.RC1-52.25.1
- (no CPE)range: < 2.1.0-17.1
- (no CPE)range: < 2.0.36.RC1-52.25.1
- (no CPE)range: < 2.1.0-17.1
- (no CPE)range: < 2.0.36.RC1-52.25.1
- (no CPE)range: < 2.1.0-17.1
- (no CPE)range: < 2.1.0-17.1
- (no CPE)range: < 5.3.17-87.1
- (no CPE)range: < 5.3.17-87.1
- (no CPE)range: < 5.3.17-87.1
- (no CPE)range: < 5.5.14-83.1
- (no CPE)range: < 5.5.14-83.1
- (no CPE)range: < 7.0.7-20.1
- (no CPE)range: < 7.0.7-20.1
Patches
Vulnerability mechanics
References
8- www.openwall.com/lists/oss-security/2016/10/15/1nvdThird Party Advisory
- www.php.net/ChangeLog-5.phpnvdRelease NotesVendor Advisory
- www.php.net/ChangeLog-7.phpnvdRelease NotesVendor Advisory
- bugs.php.net/bug.phpnvdVendor Advisory
- github.com/libgd/libgd/commit/53110871935244816bbb9d131da0bccff734bfe9nvdVendor Advisory
- www.debian.org/security/2016/dsa-3693nvd
- www.securityfocus.com/bid/93594nvd
- support.f5.com/csp/article/K21336065nvd
News mentions
0No linked articles in our index yet.