PT-2014-3368 · Php · Php

Vincent Danen

·

Published

2014-02-18

·

Updated

2014-03-08

·

CVE-2013-7328

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.5.9
Description The issue is related to multiple integer signedness errors in the gdImageCrop function, which can be exploited by remote attackers to cause a denial of service or obtain sensitive information. This can be achieved by making an imagecrop function call with a negative value for the x or y dimension.
Recommendations For versions prior to 5.5.9, update to version 5.5.9 or later to resolve the issue. As a temporary workaround, consider restricting the input values for the x and y dimensions in the imagecrop function to prevent negative values.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7328

Affected Products

Php