The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Php | — | Apply OS X security update 2005-006 | Dec 16, 2011 | May 2, 2005 |
| Gentoo Linux | — | Upgrade dev-php/mod_php.Upgrade dev-php/php-cgi.Upgrade dev-php/php. | Oct 30, 2017 | May 2, 2005 |
| Php | — | Upgrade to PHP version 4.3.11Upgrade to PHP version 5.0.4Upgrade to PHP version 4.2.3 | Oct 1, 2012 | May 2, 2005 |
| Suse | — | Upgrade php4-mysqlUpgrade php4-fastcgiUpgrade php4-pearUpgrade apache-mod_php4Upgrade php4-imapUpgrade mod_php4-coreUpgrade php4-sessionUpgrade php4-exifUpgrade mod_php4-servletUpgrade php4-sysvshmUpgrade php4-develUpgrade apache2-mod_php4 | Feb 17, 2015 | May 2, 2005 |
| Ubuntu | — | Upgrade libapache2-mod-php4 | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub