PT-2014-1418 · Php+5 · Php+5

Published

2014-03-21

·

Updated

2024-06-15

·

CVE-2014-2497

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libgd versions prior to the version that fixes the issue in the gdImageCreateFromXpm function PHP versions 5.4.26 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted color table in an XPM file. This is due to a problem in the gdImageCreateFromXpm function in gdxpm.c in libgd.
Recommendations For PHP versions 5.4.26 and earlier, consider updating to a version that includes a fix for the gdImageCreateFromXpm function issue. For libgd, as a temporary workaround, consider restricting the use of the gdImageCreateFromXpm function until a patch is available.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00373
CESA-2014_1326
CESA-2014_1327
CVE-2014-2497
DLA-189-1
DSA-3215-1
MGASA-2014-0283
MGASA-2014-0288
OPENSUSE-SU-2024:10062-1
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2014:1326
RHSA-2014:1327
RHSA-2014:1765
RHSA-2014:1766
RHSA-2014_1326
RHSA-2014_1327
SUSE-SU-2014_0868-1
SUSE-SU-2015:0370-1
SUSE-SU-2015:0436-1
SUSE-SU-2015:1018-1
SUSE-SU-2015:1265-1
USN-2987-1

Affected Products

Centos
Php
Red Hat
Suse
Ubuntu
Libgd