ISOMAN

CVE

CVE-2018-14553

gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.html
  2. https://bugzilla.redhat.com/show_bug.cgi?id=1599032
  3. https://github.com/libgd/libgd/commit/a93eac0e843148dc2d631c3ba80af17e9c8c860f
  4. https://github.com/libgd/libgd/pull/580
  5. https://lists.debian.org/debian-lts-announce/2020/02/msg00014.html
  6. https://lists.debian.org/debian-lts-announce/2024/04/msg00003.html
  7. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/
  8. https://usn.ubuntu.com/4316-1/
  9. https://usn.ubuntu.com/4316-2/
  10. http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.html
  11. https://bugzilla.redhat.com/show_bug.cgi?id=1599032
  12. https://github.com/libgd/libgd/commit/a93eac0e843148dc2d631c3ba80af17e9c8c860f
  13. https://github.com/libgd/libgd/pull/580
  14. https://lists.debian.org/debian-lts-announce/2020/02/msg00014.html
  15. https://lists.debian.org/debian-lts-announce/2024/04/msg00003.html
  16. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/
  17. https://usn.ubuntu.com/4316-1/
  18. https://usn.ubuntu.com/4316-2/