The readimagetga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.
[
{
"deprecated": false,
"source": "https://github.com/libgd/libgd/commit/fb0e0cce0b9f25389ab56604c3547351617e1415",
"id": "CVE-2016-6906-9ef5b5fe",
"signature_version": "v1",
"target": {
"function": "read_image_tga",
"file": "src/gd_tga.c"
},
"signature_type": "Function",
"digest": {
"function_hash": "313491885300404418528983452416330495039",
"length": 2283.0
}
},
{
"deprecated": false,
"source": "https://github.com/libgd/libgd/commit/fb0e0cce0b9f25389ab56604c3547351617e1415",
"id": "CVE-2016-6906-df183342",
"signature_version": "v1",
"target": {
"file": "src/gd_tga.c"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"283165936932129907493891340807525991341",
"141464916060364538192549316599818685788",
"15568252723028703085783273377507004347",
"106630161317693510202359332075049135781",
"137639860745247822653172809542557393346",
"222374484034007733712976557154961854199",
"15568252723028703085783273377507004347",
"106630161317693510202359332075049135781"
]
}
}
]