CVE-2016-9933

Impact:
Low
Public Date:
2016-12-08
CWE:
CWE-20
Bugzilla:
1404723: CVE-2016-9933 php, gd: Stack overflow in gdImageFillToBorder on truecolor images
An infinite recursion flaw was found in the gdImageFillToBorder() function from the gd library; also used by PHP imagefilltoborder() function, when passing a negative integer as the color parameter, triggering a stack overflow. A remote attacker with ability to force a negative color identifier when calling the function could crash the PHP application, causing a Denial of Service.

Find out more about CVE-2016-9933 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

CVSS v3 metrics

CVSS3 Base Score 3.3
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact Low

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Software Collections for Red Hat Enterprise Linux 6 (rh-php70-php) RHSA-2018:1296 2018-05-03
Red Hat Software Collections for Red Hat Enterprise Linux 7 (rh-php70-php) RHSA-2018:1296 2018-05-03

Affected Packages State

Platform Package State
Red Hat Software Collections for Red Hat Enterprise Linux rh-php56-php Will not fix
Red Hat OpenShift Enterprise 2 php Will not fix
Red Hat OpenShift Enterprise 2 gd Will not fix
Red Hat Enterprise Linux 7 php Will not fix
Red Hat Enterprise Linux 7 gd Will not fix
Red Hat Enterprise Linux 6 gd Will not fix
Red Hat Enterprise Linux 6 php Will not fix
Red Hat Enterprise Linux 5 gd Will not fix
Red Hat Enterprise Linux 5 php53 Will not fix
Red Hat Enterprise Linux 5 php Will not fix

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.