Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-5498


Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.


Published

2008-12-26T20:30:00.343

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application php php ≤ 5.2.8 Yes
Application php php 5 Yes
Application php php 5.0 Yes
Application php php 5.0 Yes
Application php php 5.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.0 Yes
Application php php 5.0.1 Yes
Application php php 5.0.2 Yes
Application php php 5.0.3 Yes
Application php php 5.0.4 Yes
Application php php 5.0.5 Yes
Application php php 5.1.0 Yes
Application php php 5.1.1 Yes
Application php php 5.1.2 Yes
Application php php 5.1.3 Yes
Application php php 5.1.4 Yes
Application php php 5.1.5 Yes
Application php php 5.1.6 Yes
Application php php 5.2.0 Yes
Application php php 5.2.1 Yes
Application php php 5.2.2 Yes
Application php php 5.2.3 Yes
Application php php 5.2.4 Yes
Application php php 5.2.5 Yes
Application php php 5.2.6 Yes
Application php php 5.2.7 Yes

References