VulnerabilityModified
CVE-2019-11038
This may lead to disclosing contents of the stack that has been left there by previous code.
MEDIUM 5.3EPSS 4.33%
Does this matter?
Lower severity and a low EPSS score (4.33%). Track it; it rarely justifies an emergency change on its own.
Description
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 4.33% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-457, CWE-908
- Affected
- libgd/libgd · php/php · canonical/ubuntu linux · debian/debian linux · fedoraproject/fedora · suse/linux enterprise debuginfo · opensuse/leap · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · suse/linux enterprise workstation extension · redhat/software collections · redhat/enterprise linux
- Source
- security@php.net
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3299Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929821Mailing List, Third Party Advisory
- https://bugs.php.net/bug.php?id=77973Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724149Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724432Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140118Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140120Exploit, Issue Tracking, Third Party Advisory
- https://github.com/libgd/libgd/issues/501Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00003.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKSSWFR2WPMUOIB5EN5ZM252NNEPYUTG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WAZBVK6XNYEIN7RDQXESSD63QHXPLKWL/
- https://seclists.org/bugtraq/2019/Sep/38Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4316-1/Third Party Advisory
- https://usn.ubuntu.com/4316-2/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4529Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3299Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929821Mailing List, Third Party Advisory
- https://bugs.php.net/bug.php?id=77973Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724149Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724432Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140118Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140120Exploit, Issue Tracking, Third Party Advisory
- https://github.com/libgd/libgd/issues/501Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00003.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.