ISOMAN

CVE

CVE-2019-6977

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

Severity
HIGH
CVSS
8.8
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00025.html
  2. http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00031.html
  3. http://packetstormsecurity.com/files/152459/PHP-7.2-imagecolormatch-Out-Of-Band-Heap-Write.html
  4. http://php.net/ChangeLog-5.php
  5. http://php.net/ChangeLog-7.php
  6. http://www.securityfocus.com/bid/106731
  7. https://access.redhat.com/errata/RHSA-2019:2519
  8. https://access.redhat.com/errata/RHSA-2019:3299
  9. https://bugs.php.net/bug.php?id=77270
  10. https://lists.debian.org/debian-lts-announce/2019/01/msg00028.html
  11. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/
  12. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WRUPZVT2MWFUEMVGTRAGDOBHLNMGK5R/
  13. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEYUUOW75YD3DENIPYMO263E6NL2NFHI/
  14. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TTXSLRZI5BCQT3H5KALG3DHUWUMNPDX2/
  15. https://security.gentoo.org/glsa/201903-18
  16. https://security.netapp.com/advisory/ntap-20190315-0003/
  17. https://usn.ubuntu.com/3900-1/
  18. https://www.debian.org/security/2019/dsa-4384
  19. https://www.exploit-db.com/exploits/46677/
  20. http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00025.html