gd: GIF handling buffer overflow
Published Aug 31, 2006
2.6
LOWCVSS 2.0
EPSS 8.68%
Description
Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
php-0:4.3.2-36.ent
Fixed · RHSA-2006:0669
Red Hat Enterprise Linux 4
gd-0:2.0.28-5.4E.el4_6.1
Fixed · RHSA-2008:0146
Red Hat Enterprise Linux 4
php-0:4.3.9-3.18
Fixed · RHSA-2006:0669
Red Hat Enterprise Linux 5
gd-0:2.0.33-9.4.el5_1.1
Fixed · RHSA-2008:0146
Red Hat Web Application Stack for RHEL 4
php-0:5.1.4-1.el4s1.4
Fixed · RHSA-2006:0688
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | php-0:4.3.2-36.ent | Fixed | RHSA-2006:0669 |
| Red Hat Enterprise Linux 4 | gd-0:2.0.28-5.4E.el4_6.1 | Fixed | RHSA-2008:0146 |
| Red Hat Enterprise Linux 4 | php-0:4.3.9-3.18 | Fixed | RHSA-2006:0669 |
| Red Hat Enterprise Linux 5 | gd-0:2.0.33-9.4.el5_1.1 | Fixed | RHSA-2008:0146 |
| Red Hat Web Application Stack for RHEL 4 | php-0:5.1.4-1.el4s1.4 | Fixed | RHSA-2006:0688 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (53)
- ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc vendor-advisoryx_refsource_SGI
- http://bugs.php.net/bug.php?id=38112 x_refsource_CONFIRMExploit
- http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/gd_gif_in.c?r1=1.10&r2=1.11 x_refsource_CONFIRMPatch
- http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/gd_gif_in.c?view=log x_refsource_CONFIRMPatch
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2006-0688.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/21546 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/21768 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21842 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22039 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22069 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22225 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22440 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22487 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22538 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28768 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28838 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28845 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28866 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28959 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29157 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29242 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29546 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30717 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1016984 vdb-entryx_refsource_SECTRACK
- http://support.avaya.com/elmodocs2/security/ASA-2006-222.htm x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2006-223.htm x_refsource_CONFIRM
- http://wiki.rpath.com/Advisories:rPSA-2008-0046 x_refsource_CONFIRM
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0046 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:162 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:038 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:077 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_52_php.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2008_13_sr.html vendor-advisoryx_refsource_SUSE
- http://www.php.net/ChangeLog-5.php#5.1.5 x_refsource_CONFIRM
- http://www.php.net/release_5_1_5.php x_refsource_CONFIRMPatch
- http://www.redhat.com/support/errata/RHSA-2008-0146.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/447866/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/487683/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/488008/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/19582 vdb-entryx_refsource_BID
- http://www.turbolinux.com/security/2006/TLSA-2006-38.txt vendor-advisoryx_refsource_TURBO
- http://www.ubuntu.com/usn/usn-342-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/3318 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-4484 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=431568 x_refsource_CONFIRMIssue Tracking
- https://issues.rpath.com/browse/RPL-2218 x_refsource_CONFIRM
- https://issues.rpath.com/browse/RPL-683 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-4484
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9004 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-4484
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00502.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.