CVE-2006-4484
Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow…
Does this matter?
Lower severity and a low EPSS score (8.52%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 8.52% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- php/php
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc
- http://bugs.php.net/bug.php?id=38112Exploit
- http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/gd_gif_in.c?r1=1.10&r2=1.11Patch
- http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/gd_gif_in.c?view=logPatch
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
- http://rhn.redhat.com/errata/RHSA-2006-0688.html
- http://secunia.com/advisories/21546Patch, Vendor Advisory
- http://secunia.com/advisories/21768Vendor Advisory
- http://secunia.com/advisories/21842Vendor Advisory
- http://secunia.com/advisories/22039
- http://secunia.com/advisories/22069
- http://secunia.com/advisories/22225
- http://secunia.com/advisories/22440
- http://secunia.com/advisories/22487
- http://secunia.com/advisories/22538
- http://secunia.com/advisories/28768
- http://secunia.com/advisories/28838
- http://secunia.com/advisories/28845
- http://secunia.com/advisories/28866
- http://secunia.com/advisories/28959
- http://secunia.com/advisories/29157
- http://secunia.com/advisories/29242
- http://secunia.com/advisories/29546
- http://secunia.com/advisories/30717
- http://securitytracker.com/id?1016984
- http://support.avaya.com/elmodocs2/security/ASA-2006-222.htm
- http://support.avaya.com/elmodocs2/security/ASA-2006-223.htm
- http://wiki.rpath.com/Advisories:rPSA-2008-0046
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0046
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.