The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via invalid imagecrop arguments that lead to use of a NULL pointer as a return value, a different vulnerability than CVE-2013-7226.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade php | Aug 30, 2017 | Feb 18, 2014 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Feb 18, 2014 |
| Php | — | Upgrade to PHP version 5.5.9 | Feb 26, 2014 | Feb 18, 2014 |
| Suse | — | Upgrade php7Upgrade php7-pdoUpgrade php7-pgsqlUpgrade php7-iconvUpgrade php7-sqliteUpgrade php7-mysqlUpgrade php7-tokenizerUpgrade php7-domUpgrade apache2-mod_php7Upgrade php7-develUpgrade php7-xmlreaderUpgrade php7-xmlwriterUpgrade php7-ctypeUpgrade php5-develUpgrade php72-develUpgrade php7-json | Aug 9, 2024 | Feb 18, 2014 |
| Ubuntu | — | Upgrade php5-cliUpgrade libapache2-mod-php5Upgrade php5-gdUpgrade php5-cgi | Nov 8, 2024 | Feb 18, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub