CVE-2016-5116: gd: Information leak due to stack overflow in gdCtxPrintf

Severity: Critical

CVSS Score: 9.1

gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.