Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-14553

Опубликовано: 11 фев. 2020
Источник: ubuntu
Приоритет: low
CVSS2: 4.3
CVSS3: 7.5

Описание

gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).

РелизСтатусПримечание
bionic

not-affected

code not present
devel

needed

eoan

not-affected

code not present
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

ignored

end of standard support, was needed

Показывать по

РелизСтатусПримечание
bionic

released

2.2.5-4ubuntu0.4
devel

released

2.2.5-5.2ubuntu1
eoan

released

2.2.5-5.2ubuntu0.19.10.1
esm-infra-legacy/trusty

not-affected

2.1.0-3ubuntu0.11+esm1
esm-infra/bionic

not-affected

2.2.5-4ubuntu0.4
esm-infra/focal

not-affected

2.2.5-5.2ubuntu1
esm-infra/xenial

not-affected

2.1.1-4ubuntu0.16.04.12
focal

released

2.2.5-5.2ubuntu1
groovy

released

2.2.5-5.2ubuntu1
hirsute

released

2.2.5-5.2ubuntu1

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

eoan

DNE

esm-infra-legacy/trusty

not-affected

uses system gd
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

jammy

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

not-affected

uses system gd
focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

uses system gd
devel

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

uses system gd
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

eoan

not-affected

uses system gd
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

jammy

DNE

Показывать по

4.3 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
больше 5 лет назад

gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).

CVSS3: 7.5
nvd
больше 5 лет назад

gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).

CVSS3: 7.5
debian
больше 5 лет назад

gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL point ...

CVSS3: 7.5
github
около 3 лет назад

gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing atteckers to crash an application via a specific function call sequence.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость функции gdImageClone компонента gd.c графической библиотеки LibGD, позволяющая нарушителю вызвать отказ в обслуживании

4.3 Medium

CVSS2

7.5 High

CVSS3

Уязвимость CVE-2018-14553