Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
{ "vanir_signatures": [ { "digest": { "length": 256.0, "function_hash": "194432856202509582634112016709099942790" }, "target": { "file": "src/gd_webp.c", "function": "gdImageWebpPtrEx" }, "deprecated": false, "source": "https://github.com/libgd/libgd/commit/a49feeae76d41959d85ee733925a4cf40bac61b2", "signature_version": "v1", "id": "CVE-2016-6912-1ceb8d47", "signature_type": "Function" }, { "digest": { "length": 240.0, "function_hash": "263634395288281089245221440233268892526" }, "target": { "file": "src/gd_webp.c", "function": "gdImageWebpPtr" }, "deprecated": false, "source": "https://github.com/libgd/libgd/commit/a49feeae76d41959d85ee733925a4cf40bac61b2", "signature_version": "v1", "id": "CVE-2016-6912-20b19685", "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "226314011694864228167121923027072676514", "115891090990414782721042074415808808664", "270550999008250903546546363122334472610", "165035331840864166232396677569735442872", "323194074526845233823034554452783681031", "253159594288061037863152020671000092132", "220517490509686932254282566371139298574", "229024611823301256720504633326486924855", "49350847470409066424325355585297459511", "260685879039915097948098926222053984946", "80524107107104510786750792924489434959", "273920153783671096898495713177099510304", "69301396884102556819709729200885743669", "260430200314915306155554693107514655915", "130992913157959465600679689363344875169", "125391211917661101081359825220659571510", "150572221959291443726484044644651843020", "297535411690312047760653308665145846319", "283264013521419496612609659629020243789", "328056028472638930341876244520354393728", "154522361093626086693412344659889424850", "282195283766107171985828581911887524314", "280000238423449248337798522931759000892", "259156017841268588407719744615079970615", "207969707468940408532219620355239705606", "165401882145534654389883252474120674586", "178052543393676222313287489654570762649", "306914893761560154472273876944749538878", "314637351373374929740629063029290356424", "146836403968990295987137183590878464831", "54845465767489718514097200569403208876", "192424367647884477848594017894819999824", "103168787477525203127270943579605278386", "156292238637150279986861036642602915326", "146457078312660000339683892432143312280", "5494202239218623657594591341794605167", "86421550382363043592400574939183248125", "62229571860490416194336729379296103642", "294822212921089678973169151982996393032", "117898169068602156424053768469772240017", "187569784449927878788942257498495164918", "130019454264095873297394408555768060885", "91031455532836974043864731255011363812", "187132299941885825493426592059706116319", "294295043922203891838814395406559701457", "195352474555395787924998801864664744670", "259757342006937158645403180877644294105", "113470114409076747680286142819285863266", "143503727441512041150586793506095820968", "138673491214596323821530352149190715675", "285888797987962732229995715833398004374", "77206147269506535706208285659459403687", "113470114409076747680286142819285863266" ] }, "target": { "file": "src/gd_webp.c" }, "deprecated": false, "source": "https://github.com/libgd/libgd/commit/a49feeae76d41959d85ee733925a4cf40bac61b2", "signature_version": "v1", "id": "CVE-2016-6912-30a6f371", "signature_type": "Line" }, { "digest": { "length": 1241.0, "function_hash": "149436322919130083630709859127553216096" }, "target": { "file": "src/gd_webp.c", "function": "gdImageWebpCtx" }, "deprecated": false, "source": "https://github.com/libgd/libgd/commit/a49feeae76d41959d85ee733925a4cf40bac61b2", "signature_version": "v1", "id": "CVE-2016-6912-ee5bd5eb", "signature_type": "Function" } ] }