CVE-2009-3546
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.2%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 10.21% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- libgd/gd graphics library · php/php
- Source
- secalert@redhat.com
References
- http://marc.info/?l=oss-security&m=125562113503923&w=2
- http://secunia.com/advisories/37069Vendor Advisory
- http://secunia.com/advisories/37080Vendor Advisory
- http://secunia.com/advisories/38055Vendor Advisory
- http://svn.php.net/viewvc?view=revision&revision=289557
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:285
- http://www.openwall.com/lists/oss-security/2009/11/20/5
- http://www.redhat.com/support/errata/RHSA-2010-0003.html
- http://www.securityfocus.com/bid/36712
- http://www.vupen.com/english/advisories/2009/2929Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2930Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11199
- http://marc.info/?l=oss-security&m=125562113503923&w=2
- http://secunia.com/advisories/37069Vendor Advisory
- http://secunia.com/advisories/37080Vendor Advisory
- http://secunia.com/advisories/38055Vendor Advisory
- http://svn.php.net/viewvc?view=revision&revision=289557
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:285
- http://www.openwall.com/lists/oss-security/2009/11/20/5
- http://www.redhat.com/support/errata/RHSA-2010-0003.html
- http://www.securityfocus.com/bid/36712
- http://www.vupen.com/english/advisories/2009/2929Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2930Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11199
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.