Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw98-jrc9-mrx5

Опубликовано: 14 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.

In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.

EPSS

Процентиль: 8%
0.00034
Низкий

7.1 High

CVSS3

Дефекты

CWE-125
CWE-131

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.

CVSS3: 6.5
redhat
больше 2 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

CVSS3: 6.5
nvd
больше 2 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

CVSS3: 6.5
debian
больше 2 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imagelo ...

CVSS3: 7.1
redos
больше 2 лет назад

Уязвимость PHP

EPSS

Процентиль: 8%
0.00034
Низкий

7.1 High

CVSS3

Дефекты

CWE-125
CWE-131