PT-2014-1418 · Php+5 · Php+5
Published
2014-03-21
·
Updated
2024-06-15
·
CVE-2014-2497
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libgd versions prior to the version that fixes the issue in the gdImageCreateFromXpm function
PHP versions 5.4.26 and earlier
Description
The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted color table in an XPM file. This is due to a problem in the gdImageCreateFromXpm function in gdxpm.c in libgd.
Recommendations
For PHP versions 5.4.26 and earlier, consider updating to a version that includes a fix for the gdImageCreateFromXpm function issue.
For libgd, as a temporary workaround, consider restricting the use of the gdImageCreateFromXpm function until a patch is available.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Php
Red Hat
Suse
Ubuntu
Libgd