gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00031.html
http://packetstormsecurity.com/files/152459/PHP-7.2-imagecolormatch-Out-Of-Band-Heap-Write.html
http://php.net/ChangeLog-5.php
http://php.net/ChangeLog-7.php
http://www.securityfocus.com/bid/106731
https://access.redhat.com/errata/RHSA-2019:2519
https://access.redhat.com/errata/RHSA-2019:3299
https://bugs.php.net/bug.php?id=77270
https://lists.debian.org/debian-lts-announce/2019/01/msg00028.html
https://security.gentoo.org/glsa/201903-18
https://security.netapp.com/advisory/ntap-20190315-0003/
https://usn.ubuntu.com/3900-1/
Source: MITRE
Published: 2019-01-27
Updated: 2020-08-24
Type: CWE-787
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 8.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 2.8
Severity: HIGH
OR
OR
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
147709 | NewStart CGSL MAIN 6.02 : gd Multiple Vulnerabilities (NS-SA-2021-0066) | Nessus | NewStart CGSL Local Security Checks | high |
145893 | CentOS 8 : gd (CESA-2020:4659) | Nessus | CentOS Local Security Checks | high |
143083 | RHEL 8 : gd (RHSA-2020:4659) | Nessus | Red Hat Local Security Checks | high |
142777 | Oracle Linux 8 : gd (ELSA-2020-4659) | Nessus | Oracle Linux Local Security Checks | high |
134850 | Slackware 14.2 / current : gd (SSA:2020-083-01) | Nessus | Slackware Local Security Checks | high |
131096 | Fedora 31 : gd (2019-7a06c0e6b4) | Nessus | Fedora Local Security Checks | high |
130800 | Fedora 29 : gd (2019-d7f8995451) | Nessus | Fedora Local Security Checks | high |
130792 | Fedora 30 : gd (2019-ab7d22a466) | Nessus | Fedora Local Security Checks | high |
126274 | EulerOS 2.0 SP8 : gd (EulerOS-SA-2019-1647) | Nessus | Huawei Local Security Checks | high |
125075 | Photon OS 2.0: Libgd PHSA-2019-2.0-0153 | Nessus | PhotonOS Local Security Checks | high |
124905 | EulerOS Virtualization for ARM 64 3.0.1.0 : php (EulerOS-SA-2019-1402) | Nessus | Huawei Local Security Checks | high |
123777 | openSUSE Security Update : gd (openSUSE-2019-1148) | Nessus | SuSE Local Security Checks | high |
123770 | openSUSE Security Update : gd (openSUSE-2019-1140) | Nessus | SuSE Local Security Checks | high |
123719 | EulerOS Virtualization 2.5.3 : php (EulerOS-SA-2019-1251) | Nessus | Huawei Local Security Checks | medium |
123447 | SUSE SLED15 / SLES15 Security Update : gd (SUSE-SU-2019:0771-1) | Nessus | SuSE Local Security Checks | high |
123424 | GLSA-201903-18 : GD: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
123411 | SUSE SLED12 / SLES12 Security Update : gd (SUSE-SU-2019:0747-1) | Nessus | SuSE Local Security Checks | high |
123113 | EulerOS 2.0 SP3 : php (EulerOS-SA-2019-1100) | Nessus | Huawei Local Security Checks | high |
98245 | PHP 5.6.x < 5.6.40 Multiple vulnerabilities | Web Application Scanning | Component Vulnerability | high |
98244 | PHP 7.1.x < 7.1.26 Multiple vulnerabilities | Web Application Scanning | Component Vulnerability | high |
98243 | PHP 7.2.x < 7.2.14 Multiple vulnerabilities | Web Application Scanning | Component Vulnerability | high |
98242 | PHP 7.3.x < 7.3.1 Multiple vulnerabilities | Web Application Scanning | Component Vulnerability | high |
122692 | EulerOS 2.0 SP5 : php (EulerOS-SA-2019-1069) | Nessus | Huawei Local Security Checks | medium |
122580 | openSUSE Security Update : php5 (openSUSE-2019-276) | Nessus | SuSE Local Security Checks | medium |
122533 | Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : GD vulnerabilities (USN-3900-1) | Nessus | Ubuntu Local Security Checks | high |
122394 | openSUSE Security Update : php7 (openSUSE-2019-207) | Nessus | SuSE Local Security Checks | high |
122360 | SUSE SLES12 Security Update : php5 (SUSE-SU-2019:0449-1) | Nessus | SuSE Local Security Checks | medium |
122231 | SUSE SLES11 Security Update : php53 (SUSE-SU-2019:13961-1) | Nessus | SuSE Local Security Checks | high |
122146 | SUSE SLES12 Security Update : php7 (SUSE-SU-2019:0333-1) | Nessus | SuSE Local Security Checks | high |
121602 | PHP 5.6.x < 5.6.40 Multiple vulnerabilities. | Nessus | CGI abuses | high |
121576 | Debian DSA-4384-1 : libgd2 - security update | Nessus | Debian Local Security Checks | high |
121510 | PHP 7.1.x < 7.1.26 Multiple vulnerabilities. | Nessus | CGI abuses | high |
121483 | Debian DLA-1651-1 : libgd2 security update | Nessus | Debian Local Security Checks | high |
121475 | PHP 7.3.x < 7.3.1 Multiple vulnerabilities. | Nessus | CGI abuses | high |
121353 | PHP 7.2.x < 7.2.14 Multiple vulnerabilities. | Nessus | CGI abuses | high |