Junglewise Threat Intelligence

CVE-2016-6912: libgd double free in gdImageWebPtr

CVE-2016-6912 · Severity: critical · CVSS 9.8 · Published 2017-01-26

Technologies: Libgd. Vendors: Libgd.

Executive brief

The GD Graphics Library (libgd), a widely used tool for programmatically creating and editing images, contains a vulnerability in its WebP image processing component. By providing an image with extremely large dimensions, a remote attacker can trigger a memory corruption error. This could lead to a complete system crash or allow the attacker to gain unauthorized control over the application processing the image.

Technical details

A double free vulnerability exists in the gdImageWebPtr function within libgd (GD Graphics Library) prior to version 2.2.4. The root cause is a failure in gdImageWebpCtx() to communicate success or failure states to its caller, gdImageWebpPtr(). When an image exceeds WebP's maximum dimension limits (16,383 pixels), the underlying libwebp write fails, but the calling function incorrectly assumes success and attempts to free memory that may have already been released or improperly initialized. This can be exploited by a remote, unauthenticated attacker providing a specially crafted image to trigger memory corruption, leading to a denial of service or arbitrary code execution. The issue was addressed in version 2.2.4 by introducing a helper function that properly tracks and returns the success status of the WebP context operations.

Affected products

  • libgd libgd before 2.2.4

Timeline

  • 2017-01-26: disclosed: NVD publication date
  • 2017-01-31: patched: Debian security update released

References

Related threats