CVE Vulnerabilities

CVE-2016-6912

Double Free

Published: Jan 26, 2017 | Modified: May 13, 2026
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.1 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
LibgdLibgd*2.2.3 (including)
Libgd2Ubuntuesm-infra-legacy/trusty*
Libgd2Ubuntuesm-infra-legacy/xenial*
Libgd2Ubuntuesm-infra/xenial*
Libgd2Ubuntutrusty*
Libgd2Ubuntutrusty/esm*
Libgd2Ubuntuupstream*
Libgd2Ubuntuxenial*
Libgd2Ubuntuyakkety*

Potential Mitigations

References