CVE-2016-1903

The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.
Severity
CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Atk. Vector
NETWORK
Atk. Complexity
LOW
Priv. Required
NONE
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
VendorProductVersion
phpphp
𝑥
≤ 5.5.30
phpphp
5.6.0
phpphp
5.6.0
phpphp
5.6.0
phpphp
5.6.0
phpphp
5.6.0
phpphp
5.6.0
phpphp
5.6.0
phpphp
5.6.0
phpphp
5.6.0
phpphp
5.6.1
phpphp
5.6.2
phpphp
5.6.3
phpphp
5.6.4
phpphp
5.6.5
phpphp
5.6.6
phpphp
5.6.7
phpphp
5.6.8
phpphp
5.6.9
phpphp
5.6.10
phpphp
5.6.11
phpphp
5.6.12
phpphp
5.6.13
phpphp
5.6.14
phpphp
5.6.15
phpphp
5.6.16
phpphp
7.0.0
phpphp
7.0.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libgd2
xenial
not-affected
wily
not-affected
trusty
not-affected
precise
not-affected
php5
xenial
dne
wily
Fixed 5.6.11+dfsg-1ubuntu3.2
released
vivid
ignored
trusty
Fixed 5.5.9+dfsg-1ubuntu4.16
released
precise
not-affected
php7.0
xenial
not-affected
wily
dne
vivid
dne
trusty
dne
precise
dne