← Vulnerability feed

Vulnerability record · CVE-2016-9933 · published 4 January 2017

CVE-2016-9933: Libgd memory buffer overflow vulnerability

Libgd · Libgd

Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefilltoborder call that triggers use of a negative color value.

7.5 CVSS 3.0 High EPSS 6.9% · top 6.1% CWE-119 · Memory buffer overflow
7.5CVSS 3.0 base score, v2 5.0
6.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References
17 Jun 2026Last modified by NVD

Description

Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefilltoborder call that triggers use of a negative color value.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-updates/2016-12/msg00133.html
http://lists.opensuse.org/opensuse-updates/2016-12/msg00142.html
http://lists.opensuse.org/opensuse-updates/2017-01/msg00002.html
http://lists.opensuse.org/opensuse-updates/2017-01/msg00034.html
http://lists.opensuse.org/opensuse-updates/2017-01/msg00054.html
http://www.debian.org/security/2017/dsa-3751
http://www.openwall.com/lists/oss-security/2016/12/12/2 Third Party Advisory
http://www.php.net/ChangeLog-5.php Release NotesVendor Advisory
http://www.php.net/ChangeLog-7.php Release NotesVendor Advisory
http://www.securityfocus.com/bid/94865
https://access.redhat.com/errata/RHSA-2018:1296
https://bugs.php.net/bug.php?id=72696 Vendor Advisory
https://github.com/libgd/libgd/commit/77f619d48259383628c3ec4654b1ad578e9eb40e PatchVendor Advisory
https://github.com/libgd/libgd/issues/215 Vendor Advisory
https://github.com/php/php-src/commit/863d37ea66d5c960db08d6f4a2cbd2518f0f80d1 Vendor Advisory
http://lists.opensuse.org/opensuse-updates/2016-12/msg00133.html
http://lists.opensuse.org/opensuse-updates/2016-12/msg00142.html
http://lists.opensuse.org/opensuse-updates/2017-01/msg00002.html
http://lists.opensuse.org/opensuse-updates/2017-01/msg00034.html
http://lists.opensuse.org/opensuse-updates/2017-01/msg00054.html
http://www.debian.org/security/2017/dsa-3751
http://www.openwall.com/lists/oss-security/2016/12/12/2 Third Party Advisory
http://www.php.net/ChangeLog-5.php Release NotesVendor Advisory
http://www.php.net/ChangeLog-7.php Release NotesVendor Advisory
http://www.securityfocus.com/bid/94865
https://access.redhat.com/errata/RHSA-2018:1296
https://bugs.php.net/bug.php?id=72696 Vendor Advisory
https://github.com/libgd/libgd/commit/77f619d48259383628c3ec4654b1ad578e9eb40e PatchVendor Advisory
https://github.com/libgd/libgd/issues/215 Vendor Advisory
https://github.com/php/php-src/commit/863d37ea66d5c960db08d6f4a2cbd2518f0f80d1 Vendor Advisory

Track CVE-2016-9933 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-6978Libgd double free vulnerabilityThe GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is un…EPSS 4.5%9.8CVE-2016-10166Libgd vulnerabilityInteger underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attac…EPSS 11%9.8CVE-2016-6912Libgd double free vulnerabilityDouble free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecifi…EPSS 4.5%9.8CVE-2016-8670Libgd memory buffer overflow vulnerabilityInteger signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.…EPSS 4.8%9.8CVE-2016-7568Libgd integer overflow vulnerabilityInteger overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, all…EPSS 5.1%9.8CVE-2016-3074Libgd vulnerabilityInteger signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potential…EPSS 37%9.1CVE-2016-5116Libgd memory buffer overflow vulnerabilitygd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers …EPSS 3.8%8.8CVE-2019-6977LibGD gdImageColorMatch heap buffer overflow via PHP imagecolormatchgdImageColorMatch in LibGD 2.2.5, reached through PHP's imagecolormatch function, contains a heap-based buffer overflow (CWE-787 out-of-bounds write)…EPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2016-9933), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.