Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) prior to 2.2.3, as used in PHP prior to 5.5.37, 5.6.x prior to 5.6.23, and 7.x prior to 7.0.8, allows remote malicious users to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
redhat openshift 2.0 |
||
freebsd freebsd 8.3 |
||
redhat enterprise linux 6.0 |
||
freebsd freebsd 8.0 |
||
redhat enterprise linux 5 |
||
libgd libgd 2.2.2 |
||
freebsd freebsd 10.0 |
||
fedoraproject fedora 23 |
||
debian debian linux 8.0 |
||
freebsd freebsd 10.1 |
||
fedoraproject fedora 24 |
||
freebsd freebsd 8.4 |
||
freebsd freebsd 9.2 |
||
freebsd freebsd 8.2 |
||
freebsd freebsd 8.1 |
||
freebsd freebsd 9.0 |
||
freebsd freebsd 10.2 |
||
fedoraproject fedora 22 |
||
freebsd freebsd 9.3 |
||
redhat enterprise linux 7.0 |
||
freebsd freebsd 10.3 |
||
freebsd freebsd 9.1 |