Логотип exploitDog
bind:CVE-2017-7890
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-7890

Количество 13

Количество 13

ubuntu логотип

CVE-2017-7890

почти 8 лет назад

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2017-7890

почти 8 лет назад

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 5.5
EPSS: Средний
nvd логотип

CVE-2017-7890

почти 8 лет назад

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2017-7890

почти 8 лет назад

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in th ...

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2cx4-qmrc-3ff4

около 3 лет назад

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 6.5
EPSS: Средний
oracle-oval логотип

ELSA-2018-0406

больше 7 лет назад

ELSA-2018-0406: php security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2018-00008

около 8 лет назад

Уязвимость функции GIF-декодирования gdImageCreateFromGifCtx (gd_gif_in.c) библиотеки для создания и работы с программируемой графикой libgd2, позволяющая нарушителю нарушить конфиденциальность информации

CVSS3: 6.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2020:0623-1

больше 5 лет назад

Security update for gd

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:2366-1

почти 8 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:2337-1

почти 8 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2317-1

почти 8 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2303-1

почти 8 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2522-1

почти 8 лет назад

Security update for php53

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-7890

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 6.5
11%
Средний
почти 8 лет назад
redhat логотип
CVE-2017-7890

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 5.5
11%
Средний
почти 8 лет назад
nvd логотип
CVE-2017-7890

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 6.5
11%
Средний
почти 8 лет назад
debian логотип
CVE-2017-7890

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in th ...

CVSS3: 6.5
11%
Средний
почти 8 лет назад
github логотип
GHSA-2cx4-qmrc-3ff4

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 6.5
11%
Средний
около 3 лет назад
oracle-oval логотип
ELSA-2018-0406

ELSA-2018-0406: php security update (MODERATE)

больше 7 лет назад
fstec логотип
BDU:2018-00008

Уязвимость функции GIF-декодирования gdImageCreateFromGifCtx (gd_gif_in.c) библиотеки для создания и работы с программируемой графикой libgd2, позволяющая нарушителю нарушить конфиденциальность информации

CVSS3: 6.5
11%
Средний
около 8 лет назад
suse-cvrf логотип
SUSE-SU-2020:0623-1

Security update for gd

больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2366-1

Security update for php5

почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2337-1

Security update for php7

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2317-1

Security update for php5

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2303-1

Security update for php7

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2522-1

Security update for php53

почти 8 лет назад

Уязвимостей на страницу