Integer overflow in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an imagecrop function call with a large x dimension value, leading to a heap-based buffer overflow.
http://git.php.net/?p=php-src.git;a=commit;h=8f4a5373bb71590352fd934028d6dde5bc18530b
http://secunia.com/advisories/56829
http://www.mandriva.com/security/advisories?name=MDVSA-2014:027
http://www.php.net/ChangeLog-5.php
http://www.securityfocus.com/bid/65533
http://www.securitytracker.com/id/1029767
http://www.ubuntu.com/usn/USN-2126-1
https://bugs.php.net/bug.php?id=66356
https://bugzilla.redhat.com/show_bug.cgi?id=1065108
https://exchange.xforce.ibmcloud.com/vulnerabilities/91099
https://github.com/php/php-src/commit/2938329ce19cb8c4197dec146c3ec887c6f61d01
OR
cpe:2.3:a:php:php:5.5.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta3:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta4:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:rc1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:rc2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.2:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.3:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.4:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.5:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.6:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
78556 | PHP 5.6.0 Multiple Vulnerabilities | Nessus | CGI abuses | high |
77455 | GLSA-201408-11 : PHP: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
72799 | Ubuntu 10.04 LTS / 12.04 LTS / 12.10 / 13.10 : php5 vulnerabilities (USN-2126-1) | Nessus | Ubuntu Local Security Checks | medium |
8125 | PHP 5.5.x < 5.5.9 GD Extension Multiple Vulnerabilities | Nessus Network Monitor | Web Servers | high |
72511 | PHP 5.5.x < 5.5.9 GD Extension Multiple Vulnerabilities | Nessus | CGI abuses | medium |
72468 | Mandriva Linux Security Advisory : php (MDVSA-2014:027) | Nessus | Mandriva Local Security Checks | medium |