CVE-2016-10166: gd: Unsigned integer underflow _gdContributionsAlloc()

Severity: Critical

CVSS Score: 9.8

Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.