Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw98-jrc9-mrx5

Опубликовано: 14 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.

In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.

EPSS

Процентиль: 19%
0.00061
Низкий

7.1 High

CVSS3

Дефекты

CWE-125
CWE-131

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 3 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.

CVSS3: 6.5
redhat
около 3 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

CVSS3: 6.5
nvd
около 3 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

CVSS3: 6.5
debian
около 3 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imagelo ...

CVSS3: 7.1
fstec
около 3 лет назад

Уязвимость функции imageloadfont() интерпретатора языка программирования PHP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.00061
Низкий

7.1 High

CVSS3

Дефекты

CWE-125
CWE-131