Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-6977

Опубликовано: 09 дек. 2018
Источник: redhat
CVSS3: 6.3

Описание

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gdWill not fix
Red Hat Enterprise Linux 5phpWill not fix
Red Hat Enterprise Linux 5php53Will not fix
Red Hat Enterprise Linux 6gdWill not fix
Red Hat Enterprise Linux 6phpWill not fix
Red Hat Enterprise Linux 7gdNot affected
Red Hat Enterprise Linux 7phpWill not fix
Red Hat Enterprise Linux 8php:7.2/phpNot affected
Red Hat Software Collectionsrh-php70-phpWill not fix
Red Hat Enterprise Linux 8gdFixedRHSA-2020:465904.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1672207gd: Heap-based buffer overflow in gdImageColorMatch() in gd_color_match.c

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 6 лет назад

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

CVSS3: 8.8
nvd
больше 6 лет назад

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

CVSS3: 8.8
debian
больше 6 лет назад

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka ...

suse-cvrf
больше 6 лет назад

Security update for php5

suse-cvrf
больше 6 лет назад

Security update for php5

6.3 Medium

CVSS3

Уязвимость CVE-2019-6977