Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-1903

31
FAUCET Score

CVE-2016-1903 is an out-of-bounds read vulnerability affecting the gdImageRotateInterpolated function in PHP versions before 5.5.31, 5.6.17, and 7.0.2. A remote attacker can trigger this flaw by providing a large bgd_color argument to the imagerotate function, leading to sensitive information disclosure or a denial of service (application crash). This vulnerability carries a critical CVSS score of 9.1, indicating a severe impact with high confidentiality and availability concerns, and can be exploited over the network with low attack complexity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the CVE has garnered significant community discussion, suggesting awareness among security researchers.

Impacted Technologies

VendorProductVersion(s)CPE
<= 5.5.30CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
5.6.0CPE matchmatch criteria
cpe:2.3:a:php:php:5.6.0:alpha1:*:*:*:*:*:*
5.6.0CPE matchmatch criteria
cpe:2.3:a:php:php:5.6.0:alpha2:*:*:*:*:*:*
5.6.0CPE matchmatch criteria
cpe:2.3:a:php:php:5.6.0:alpha3:*:*:*:*:*:*
5.6.0CPE matchmatch criteria
cpe:2.3:a:php:php:5.6.0:alpha4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.1CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.0

Exploit Intelligence

EPSS Score
7.81%
Probability of exploitation in next 30 days
EPSS Percentile
94.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0781 is in the 89th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-php56-0:2.3-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-php56-php-0:5.6.25-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-php56-php-pear-1:1.9.5-4.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-php56-0:2.3-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-php56-php-0:5.6.25-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-php56-php-pear-1:1.9.5-4.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-php56-0:2.3-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-php56-php-0:5.6.25-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-php56-php-pear-1:1.9.5-4.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSFixed in: rh-php56-0:2.3-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSFixed in: rh-php56-php-0:5.6.25-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSFixed in: rh-php56-php-pear-1:1.9.5-4.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSFixed in: rh-php56-0:2.3-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSFixed in: rh-php56-php-0:5.6.25-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSFixed in: rh-php56-php-pear-1:1.9.5-4.el7
View patch
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: php55-php

Vendor Advisories (1)

redhatCVE-2016-1903Moderate

php: Out-of-bounds memory read via gdImageRotateInterpolated

Nov 26, 2015

References

lists.opensuse.org / opensuse-updates/2016-01/msg00099.html
lists.opensuse.org / opensuse-updates/2016-02/msg00037.html
rhn.redhat.com / errata/RHSA-2016-2750.html
bugs.php.net / bug.php
Exploit
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
openwall.com / lists/oss-security/2016/01/14/8
php.net / ChangeLog-5.php
Vendor Advisory
php.net / ChangeLog-7.php
Vendor Advisory
securityfocus.com / bid/79916
securitytracker.com / id/1034608
slackware.com / security/viewer.php
ubuntu.com / usn/USN-2952-1
ubuntu.com / usn/USN-2952-2