gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gd | Oct 1, 2024 | Aug 7, 2016 |
| Debian | — | Upgrade libgd2 | Jul 15, 2016 | Jul 15, 2016 |
| Suse | — | Upgrade libgd3Upgrade gd-32bitUpgrade gd-develUpgrade gdUpgrade libgd3-32bit | Aug 7, 2016 | Aug 7, 2016 |
| Ubuntu | — | Upgrade libgd2-noxpmUpgrade libgd3Upgrade libgd2-xpm | Jul 11, 2016 | Jul 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub