PT-2014-1418 · Php+5 · Php+5

Publicado

2014-03-21

·

Atualizado

2024-06-15

·

CVE-2014-2497

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libgd versions prior to the version that fixes the issue in the gdImageCreateFromXpm function PHP versions 5.4.26 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted color table in an XPM file. This is due to a problem in the gdImageCreateFromXpm function in gdxpm.c in libgd.
Recommendations For PHP versions 5.4.26 and earlier, consider updating to a version that includes a fix for the gdImageCreateFromXpm function issue. For libgd, as a temporary workaround, consider restricting the use of the gdImageCreateFromXpm function until a patch is available.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00373
CESA-2014_1326
CESA-2014_1327
CVE-2014-2497
DLA-189-1
DSA-3215-1
MGASA-2014-0283
MGASA-2014-0288
OPENSUSE-SU-2024:10062-1
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2014:1326
RHSA-2014:1327
RHSA-2014:1765
RHSA-2014:1766
RHSA-2014_1326
RHSA-2014_1327
SUSE-SU-2014_0868-1
SUSE-SU-2015:0370-1
SUSE-SU-2015:0436-1
SUSE-SU-2015:1018-1
SUSE-SU-2015:1265-1
USN-2987-1

Produtos afetados

Centos
Php
Red Hat
Suse
Ubuntu
Libgd