CVE Vulnerabilities

CVE-2016-6912

Double Free

Published: Jan 26, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.1 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
LibgdLibgd*2.2.3 (including)
Libgd2Ubuntuesm-infra-legacy/trusty*
Libgd2Ubuntuesm-infra/xenial*
Libgd2Ubuntutrusty*
Libgd2Ubuntutrusty/esm*
Libgd2Ubuntuupstream*
Libgd2Ubuntuxenial*
Libgd2Ubuntuyakkety*

Potential Mitigations

References