5
CVSSv2

CVE-2008-5498

Published: 26/12/2008 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Array index error in the imageRotate function in PHP 5.2.8 and previous versions allows context-dependent malicious users to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.1.3

php php 5.1.2

php php 5.2.1

php php 5.2.2

php php 5.0

php php 5.0.2

php php 5.0.1

php php 5.0.0

php php 5.2.6

php php 5.2.5

php php 5.1.6

php php 5.2.0

php php 5.0.4

php php 5.0.3

php php

php php 5.1.1

php php 5.1.0

php php 5.0.5

php php 5

php php 5.2.7

php php 5.2.4

php php 5.2.3

php php 5.1.4

php php 5.1.5

Vendor Advisories

Synopsis Moderate: php security update Type/Severity Security Advisory: Moderate Topic Updated php packages that fix several security issues are now available forRed Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Descriptio ...

Exploits

PHP - gd library - imageRotate()function Information Leak Vulnerability Discovered by: Hamid Ebadi, Further research and exploit: Mohammad R Roohian CSIRT Team Members Amirkabir University APA Laboratory Introduction PHP is a popular web programming language which isnormally used as a script engine in the server side PHP 5 which is compiledwit ...