PT-2014-1418 · Php+5 · Php+5
Publicado
2014-03-21
·
Atualizado
2024-06-15
·
CVE-2014-2497
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libgd versions prior to the version that fixes the issue in the gdImageCreateFromXpm function
PHP versions 5.4.26 and earlier
Description
The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted color table in an XPM file. This is due to a problem in the gdImageCreateFromXpm function in gdxpm.c in libgd.
Recommendations
For PHP versions 5.4.26 and earlier, consider updating to a version that includes a fix for the gdImageCreateFromXpm function issue.
For libgd, as a temporary workaround, consider restricting the use of the gdImageCreateFromXpm function until a patch is available.
Exploit
Correção
DoS
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Php
Red Hat
Suse
Ubuntu
Libgd