{"id":"CVE-2016-7568","details":"Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.","modified":"2026-05-17T11:54:55.256368464Z","published":"2016-09-28T20:59:02.680Z","related":["SUSE-SU-2016:2668-1","SUSE-SU-2016:2683-1","SUSE-SU-2016:2683-2","SUSE-SU-2016:2766-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"8.0"}],"source":"CPE_FIELD","vendor_product":"debian:debian_linux"}]},"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3693"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/93184"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201612-09"},{"type":"REPORT","url":"https://bugs.php.net/bug.php?id=73003"},{"type":"FIX","url":"https://github.com/libgd/libgd/commit/40bec0f38f50e8510f5bb71a82f516d46facde03"},{"type":"FIX","url":"https://github.com/libgd/libgd/issues/308"},{"type":"FIX","url":"https://github.com/php/php-src/commit/c18263e0e0769faee96a5d0ee04b750c442783c6"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}