CVE-2019-6977

MEDIUM

Description

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

References

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00025.html

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00031.html

http://packetstormsecurity.com/files/152459/PHP-7.2-imagecolormatch-Out-Of-Band-Heap-Write.html

http://php.net/ChangeLog-5.php

http://php.net/ChangeLog-7.php

http://www.securityfocus.com/bid/106731

https://access.redhat.com/errata/RHSA-2019:2519

https://access.redhat.com/errata/RHSA-2019:3299

https://bugs.php.net/bug.php?id=77270

https://lists.debian.org/debian-lts-announce/2019/01/msg00028.html

https://lists.fedoraproject.org/archives/list/[email protected]/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/

https://lists.fedoraproject.org/archives/list/[email protected]/message/3WRUPZVT2MWFUEMVGTRAGDOBHLNMGK5R/

https://lists.fedoraproject.org/archives/list/[email protected]/message/TEYUUOW75YD3DENIPYMO263E6NL2NFHI/

https://lists.fedoraproject.org/archives/list/[email protected]/message/TTXSLRZI5BCQT3H5KALG3DHUWUMNPDX2/

https://security.gentoo.org/glsa/201903-18

https://security.netapp.com/advisory/ntap-20190315-0003/

https://usn.ubuntu.com/3900-1/

https://www.debian.org/security/2019/dsa-4384

https://www.exploit-db.com/exploits/46677/

Details

Source: MITRE

Published: 2019-01-27

Updated: 2020-08-24

Type: CWE-787

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (35 total)

IDNameProductFamilySeverity
147709NewStart CGSL MAIN 6.02 : gd Multiple Vulnerabilities (NS-SA-2021-0066)NessusNewStart CGSL Local Security Checks
high
145893CentOS 8 : gd (CESA-2020:4659)NessusCentOS Local Security Checks
high
143083RHEL 8 : gd (RHSA-2020:4659)NessusRed Hat Local Security Checks
high
142777Oracle Linux 8 : gd (ELSA-2020-4659)NessusOracle Linux Local Security Checks
high
134850Slackware 14.2 / current : gd (SSA:2020-083-01)NessusSlackware Local Security Checks
high
131096Fedora 31 : gd (2019-7a06c0e6b4)NessusFedora Local Security Checks
high
130800Fedora 29 : gd (2019-d7f8995451)NessusFedora Local Security Checks
high
130792Fedora 30 : gd (2019-ab7d22a466)NessusFedora Local Security Checks
high
126274EulerOS 2.0 SP8 : gd (EulerOS-SA-2019-1647)NessusHuawei Local Security Checks
high
125075Photon OS 2.0: Libgd PHSA-2019-2.0-0153NessusPhotonOS Local Security Checks
high
124905EulerOS Virtualization for ARM 64 3.0.1.0 : php (EulerOS-SA-2019-1402)NessusHuawei Local Security Checks
high
123777openSUSE Security Update : gd (openSUSE-2019-1148)NessusSuSE Local Security Checks
high
123770openSUSE Security Update : gd (openSUSE-2019-1140)NessusSuSE Local Security Checks
high
123719EulerOS Virtualization 2.5.3 : php (EulerOS-SA-2019-1251)NessusHuawei Local Security Checks
medium
123447SUSE SLED15 / SLES15 Security Update : gd (SUSE-SU-2019:0771-1)NessusSuSE Local Security Checks
high
123424GLSA-201903-18 : GD: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
123411SUSE SLED12 / SLES12 Security Update : gd (SUSE-SU-2019:0747-1)NessusSuSE Local Security Checks
high
123113EulerOS 2.0 SP3 : php (EulerOS-SA-2019-1100)NessusHuawei Local Security Checks
high
98245PHP 5.6.x < 5.6.40 Multiple vulnerabilitiesWeb Application ScanningComponent Vulnerability
high
98244PHP 7.1.x < 7.1.26 Multiple vulnerabilitiesWeb Application ScanningComponent Vulnerability
high
98243PHP 7.2.x < 7.2.14 Multiple vulnerabilitiesWeb Application ScanningComponent Vulnerability
high
98242PHP 7.3.x < 7.3.1 Multiple vulnerabilitiesWeb Application ScanningComponent Vulnerability
high
122692EulerOS 2.0 SP5 : php (EulerOS-SA-2019-1069)NessusHuawei Local Security Checks
medium
122580openSUSE Security Update : php5 (openSUSE-2019-276)NessusSuSE Local Security Checks
medium
122533Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : GD vulnerabilities (USN-3900-1)NessusUbuntu Local Security Checks
high
122394openSUSE Security Update : php7 (openSUSE-2019-207)NessusSuSE Local Security Checks
high
122360SUSE SLES12 Security Update : php5 (SUSE-SU-2019:0449-1)NessusSuSE Local Security Checks
medium
122231SUSE SLES11 Security Update : php53 (SUSE-SU-2019:13961-1)NessusSuSE Local Security Checks
high
122146SUSE SLES12 Security Update : php7 (SUSE-SU-2019:0333-1)NessusSuSE Local Security Checks
high
121602PHP 5.6.x < 5.6.40 Multiple vulnerabilities.NessusCGI abuses
high
121576Debian DSA-4384-1 : libgd2 - security updateNessusDebian Local Security Checks
high
121510PHP 7.1.x < 7.1.26 Multiple vulnerabilities.NessusCGI abuses
high
121483Debian DLA-1651-1 : libgd2 security updateNessusDebian Local Security Checks
high
121475PHP 7.3.x < 7.3.1 Multiple vulnerabilities.NessusCGI abuses
high
121353PHP 7.2.x < 7.2.14 Multiple vulnerabilities.NessusCGI abuses
high