Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
[
{
"source": "https://github.com/libgd/libgd/commit/a49feeae76d41959d85ee733925a4cf40bac61b2",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "gdImageWebpPtrEx",
"file": "src/gd_webp.c"
},
"id": "CVE-2016-6912-1ceb8d47",
"digest": {
"length": 256.0,
"function_hash": "194432856202509582634112016709099942790"
},
"signature_type": "Function"
},
{
"source": "https://github.com/libgd/libgd/commit/a49feeae76d41959d85ee733925a4cf40bac61b2",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "gdImageWebpPtr",
"file": "src/gd_webp.c"
},
"id": "CVE-2016-6912-20b19685",
"digest": {
"length": 240.0,
"function_hash": "263634395288281089245221440233268892526"
},
"signature_type": "Function"
},
{
"source": "https://github.com/libgd/libgd/commit/a49feeae76d41959d85ee733925a4cf40bac61b2",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "src/gd_webp.c"
},
"id": "CVE-2016-6912-30a6f371",
"digest": {
"threshold": 0.9,
"line_hashes": [
"226314011694864228167121923027072676514",
"115891090990414782721042074415808808664",
"270550999008250903546546363122334472610",
"165035331840864166232396677569735442872",
"323194074526845233823034554452783681031",
"253159594288061037863152020671000092132",
"220517490509686932254282566371139298574",
"229024611823301256720504633326486924855",
"49350847470409066424325355585297459511",
"260685879039915097948098926222053984946",
"80524107107104510786750792924489434959",
"273920153783671096898495713177099510304",
"69301396884102556819709729200885743669",
"260430200314915306155554693107514655915",
"130992913157959465600679689363344875169",
"125391211917661101081359825220659571510",
"150572221959291443726484044644651843020",
"297535411690312047760653308665145846319",
"283264013521419496612609659629020243789",
"328056028472638930341876244520354393728",
"154522361093626086693412344659889424850",
"282195283766107171985828581911887524314",
"280000238423449248337798522931759000892",
"259156017841268588407719744615079970615",
"207969707468940408532219620355239705606",
"165401882145534654389883252474120674586",
"178052543393676222313287489654570762649",
"306914893761560154472273876944749538878",
"314637351373374929740629063029290356424",
"146836403968990295987137183590878464831",
"54845465767489718514097200569403208876",
"192424367647884477848594017894819999824",
"103168787477525203127270943579605278386",
"156292238637150279986861036642602915326",
"146457078312660000339683892432143312280",
"5494202239218623657594591341794605167",
"86421550382363043592400574939183248125",
"62229571860490416194336729379296103642",
"294822212921089678973169151982996393032",
"117898169068602156424053768469772240017",
"187569784449927878788942257498495164918",
"130019454264095873297394408555768060885",
"91031455532836974043864731255011363812",
"187132299941885825493426592059706116319",
"294295043922203891838814395406559701457",
"195352474555395787924998801864664744670",
"259757342006937158645403180877644294105",
"113470114409076747680286142819285863266",
"143503727441512041150586793506095820968",
"138673491214596323821530352149190715675",
"285888797987962732229995715833398004374",
"77206147269506535706208285659459403687",
"113470114409076747680286142819285863266"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/libgd/libgd/commit/a49feeae76d41959d85ee733925a4cf40bac61b2",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "gdImageWebpCtx",
"file": "src/gd_webp.c"
},
"id": "CVE-2016-6912-ee5bd5eb",
"digest": {
"length": 1241.0,
"function_hash": "149436322919130083630709859127553216096"
},
"signature_type": "Function"
}
]