gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gd | Oct 1, 2024 | Aug 7, 2016 |
| Debian | — | Upgrade libgd2 | Jul 15, 2016 | Jul 15, 2016 |
| Suse | — | Upgrade libgd3Upgrade libgd3-32bitUpgrade gd-32bitUpgrade gd-develUpgrade gd | Aug 7, 2016 | Aug 7, 2016 |
| Ubuntu | — | Upgrade libgd2-noxpmUpgrade libgd2-xpmUpgrade libgd3 | Jul 11, 2016 | Jul 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub