Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5711

Опубликовано: 16 янв. 2018
Источник: debian

Описание

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.1fixed7.1.13-1package
php7.0fixed7.0.27-1package
php5removedpackage
hhvmfixed3.24.7+dfsg-1package
libgd2fixed2.2.5-4.1package
libgd2fixed2.2.4-2+deb9u3stretchpackage

Примечания

  • Fixed in 5.6.33, 7.0.27, 7.1.13, 7.2.1

  • PHP Bug: https://bugs.php.net/bug.php?id=75571

  • https://hhvm.com/blog/2018/05/04/hhvm-3.25.3.html

  • https://github.com/libgd/libgd/issues/420

  • https://github.com/libgd/libgd/commit/a11f47475e6443b7f32d21f2271f28f417e2ac04

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.

CVSS3: 4.3
redhat
больше 7 лет назад

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.

CVSS3: 5.5
nvd
больше 7 лет назад

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.

suse-cvrf
больше 7 лет назад

Security update for gd

suse-cvrf
больше 7 лет назад

Security update for gd