Integer overflow in the gdImageCreate function in gd.c in the GD Graphics Library (aka libgd) prior to 2.0.34RC1, as used in PHP prior to 5.5.37, 5.6.x prior to 5.6.23, and 7.x prior to 7.0.8, allows remote malicious users to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted image dimensions.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
libgd libgd |