« List of all CVEs

CVE-2019-11038

Uninitialized read in gdImageCreateFromXbm

Published: 6/18/2019 Last updated: 9/16/2024 Reserved: 4/9/2019

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.

CNA assigner: php (dd77f84a-d19a-4638-8c3d-a322d820ed2b) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 3.1 Low CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Opam packages affected (1)

conf-gd

Products affected (1)

Product Vendor Version
PHP PHP Group 22.0 ap378886

References (36)

Credits (1)