- Fix stack based buffer overflow when passing negative `rlen` as size to memcpy() (CVE-2016-8670) - Fix possible overflow in gdImageWebpCtx (CVE-2016-7568)