VulnerabilityModified
CVE-2014-2497
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
MEDIUM 4.3EPSS 20.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 20.19% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- php/php · canonical/ubuntu linux · suse/linux enterprise server · suse/linux enterprise software development kit · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · debian/debian linux · oracle/solaris
- Source
- cve@mitre.org
References
- http://advisories.mageia.org/MGASA-2014-0288.htmlThird Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlBroken Link, Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1326.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1327.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1765.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1766.htmlThird Party Advisory
- http://secunia.com/advisories/59061Not Applicable
- http://secunia.com/advisories/59418Not Applicable
- http://secunia.com/advisories/59496Not Applicable
- http://secunia.com/advisories/59652Not Applicable
- http://www.debian.org/security/2015/dsa-3215Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:153Broken Link
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlThird Party Advisory
- http://www.securityfocus.com/bid/66233Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2987-1Third Party Advisory
- https://bugs.php.net/bug.php?id=66901Exploit, Issue Tracking, Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1076676Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201607-04Third Party Advisory
- https://support.apple.com/HT204659Third Party Advisory
- http://advisories.mageia.org/MGASA-2014-0288.htmlThird Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlBroken Link, Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1326.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1327.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1765.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-1766.htmlThird Party Advisory
- http://secunia.com/advisories/59061Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.