gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.
2016-08-07T10:59:12.257
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:N/A:P
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | libgd | libgd | ≤ 2.2.1 | Yes |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.0 | No |
Application | php | php | 5.5.1 | No |
Application | php | php | 5.5.2 | No |
Application | php | php | 5.5.3 | No |
Application | php | php | 5.5.4 | No |
Application | php | php | 5.5.5 | No |
Application | php | php | 5.5.6 | No |
Application | php | php | 5.5.7 | No |
Application | php | php | 5.5.8 | No |
Application | php | php | 5.5.9 | No |
Application | php | php | 5.5.10 | No |
Application | php | php | 5.5.11 | No |
Application | php | php | 5.5.12 | No |
Application | php | php | 5.5.13 | No |
Application | php | php | 5.5.14 | No |
Application | php | php | 5.5.18 | No |
Application | php | php | 5.5.19 | No |
Application | php | php | 5.5.20 | No |
Application | php | php | 5.5.21 | No |
Application | php | php | 5.5.22 | No |
Application | php | php | 5.5.23 | No |
Application | php | php | 5.5.24 | No |
Application | php | php | 5.5.25 | No |
Application | php | php | 5.5.26 | No |
Application | php | php | 5.5.27 | No |
Application | php | php | 5.5.28 | No |
Application | php | php | 5.5.29 | No |
Application | php | php | 5.5.30 | No |
Application | php | php | 5.5.31 | No |
Application | php | php | 5.5.32 | No |
Application | php | php | 5.5.33 | No |
Application | php | php | 5.5.34 | No |
Application | php | php | 5.5.35 | No |
Application | php | php | 5.5.37 | No |
Operating System | opensuse | leap | 42.1 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |