gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted image that is mishandled by the imagescale function.
CVSS Details
- CVSS 3.1 Base Score: 7.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade php56Upgrade php55 | Jun 15, 2016 | Jun 2, 2016 |
| Apple Osx Apachemodphp | — | Apply OS X security update 2016-004Upgrade macOS to the latest version | Nov 11, 2016 | Aug 7, 2016 |
| Debian | — | Upgrade libgd2 | Jun 14, 2016 | Jun 14, 2016 |
| Freebsd | — | Upgrade php70-intlUpgrade php55-gdUpgrade php55Upgrade php56Upgrade php56-gdUpgrade php55-pharUpgrade php70-gd | Dec 10, 2025 | May 28, 2016 |
| Php | — | Upgrade to PHP version 5.5.36Upgrade to PHP version 5.6.22 | Sep 30, 2019 | Aug 7, 2016 |
| Suse | — | Upgrade php5-tokenizerUpgrade php5-mssql-debuginfoUpgrade php5-soapUpgrade php5-pcntl-debuginfoUpgrade php5-mysqlUpgrade php5-pcntlUpgrade php5-ftp-debuginfoUpgrade php5-fileinfoUpgrade php5-zip-debuginfoUpgrade php5-fpmUpgrade php5-sqliteUpgrade php5-mssqlUpgrade php5-sysvshm-debuginfoUpgrade imap-debuginfoUpgrade php5-xmlreader-debuginfoUpgrade php5-bz2-debuginfoUpgrade php5-odbcUpgrade php5-xmlrpc-debuginfoUpgrade php5-gdUpgrade php5-ldapUpgrade php5-curlUpgrade php5-shmopUpgrade php5-curl-debuginfoUpgrade php5-pgsql-debuginfoUpgrade php5-xsl-debuginfoUpgrade php5-intl-debuginfoUpgrade php5-mbstring-debuginfoUpgrade php5-firebirdUpgrade php5-snmpUpgrade php5-dba-debuginfoUpgrade php5-enchantUpgrade libc-client2007e_suse-debuginfoUpgrade php5-readlineUpgrade php5-fileinfo-debuginfoUpgrade php5-dbaUpgrade imap-develUpgrade php5-opcacheUpgrade php5-calendarUpgrade php5-sockets-debuginfoUpgrade php5-ctype-debuginfoUpgrade php5-odbc-debuginfoUpgrade php5Upgrade php5-gmp-debuginfoUpgrade php5-firebird-debuginfoUpgrade php5-suhosinUpgrade php5-zlib-debuginfoUpgrade php5-gmpUpgrade php5-zlibUpgrade php5-gettext-debuginfoUpgrade apache2-mod_php5-debuginfoUpgrade php5-sysvmsg-debuginfoUpgrade php5-develUpgrade php5-gd-debuginfoUpgrade php5-pgsqlUpgrade php5-readline-debuginfoUpgrade php5-opcache-debuginfoUpgrade php5-pspellUpgrade php5-soap-debuginfoUpgrade php5-mcryptUpgrade php5-bz2Upgrade php5-xmlwriter-debuginfoUpgrade php5-sysvsemUpgrade php5-ctypeUpgrade php5-phar-debuginfoUpgrade php5-domUpgrade apache2-mod_php5Upgrade php5-json-debuginfoUpgrade php5-calendar-debuginfoUpgrade php5-dom-debuginfoUpgrade php5-ftpUpgrade php5-fastcgi-debuginfoUpgrade php5-debugsourceUpgrade php5-tokenizer-debuginfoUpgrade php5-wddxUpgrade php5-jsonUpgrade libc-client2007e_suseUpgrade php5-bcmath-debuginfoUpgrade php5-socketsUpgrade imapUpgrade php5-sysvsem-debuginfoUpgrade php5-imap-debuginfoUpgrade php5-sysvmsgUpgrade php5-iconv-debuginfoUpgrade php5-exifUpgrade php5-snmp-debuginfoUpgrade php5-debuginfoUpgrade php5-xmlreaderUpgrade php5-sysvshmUpgrade php5-suhosin-debuginfoUpgrade php5-pdo-debuginfoUpgrade php5-fpm-debuginfoUpgrade php5-zipUpgrade php5-shmop-debuginfoUpgrade php5-openssl-debuginfoUpgrade php5-fastcgiUpgrade php5-mysql-debuginfoUpgrade php5-pdoUpgrade php5-tidyUpgrade php5-pearUpgrade php5-pspell-debuginfoUpgrade php5-wddx-debuginfoUpgrade php5-mcrypt-debuginfoUpgrade php5-mbstringUpgrade php5-posix-debuginfoUpgrade php5-sqlite-debuginfoUpgrade php5-ldap-debuginfoUpgrade php5-pharUpgrade imap-debugsourceUpgrade php5-enchant-debuginfoUpgrade php5-iconvUpgrade php5-intlUpgrade php5-xmlwriterUpgrade php5-posixUpgrade php5-opensslUpgrade php5-imapUpgrade php5-xslUpgrade php5-bcmathUpgrade php5-exif-debuginfoUpgrade php5-gettextUpgrade php5-xmlrpcUpgrade php5-tidy-debuginfo | Apr 26, 2018 | Jun 20, 2016 |
| Ubuntu | — | Upgrade libgd2-noxpmUpgrade libgd2-xpmUpgrade libgd3 | Jul 11, 2016 | Jul 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub