HIGH
gd: NULL pointer dereference in gdImageClone
Published Feb 11, 2020
7.5
HIGHCVSS 3.1
EPSS 3.44%
Description
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
Affected products
No data.
Configuration 1
Configuration 2
- 32
Configuration 3
OR
- 14.04
- 16.04
- 18.04
- 19.10
Configuration 4
- 8.0
No data.
Red Hat Enterprise Linux 8
gd-0:2.2.5-7.el8
Fixed · RHSA-2020:4659
Red Hat Enterprise Linux 5
gd
Not affected
Red Hat Enterprise Linux 6
gd
Not affected
Red Hat Enterprise Linux 7
gd
Not affected
Red Hat Software Collections
rh-php70-php
Not affected
Red Hat Software Collections
rh-php71-php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | gd-0:2.2.5-7.el8 | Fixed | RHSA-2020:4659 |
| Red Hat Enterprise Linux 5 | gd | Not affected | n/a |
| Red Hat Enterprise Linux 6 | gd | Not affected | n/a |
| Red Hat Enterprise Linux 7 | gd | Not affected | n/a |
| Red Hat Software Collections | rh-php70-php | Not affected | n/a |
| Red Hat Software Collections | rh-php71-php | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (14)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.html vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-14553 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1599032 Issue TrackingPermissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=1600727 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-6462 Advisory
- https://github.com/libgd/libgd/commit/a93eac0e843148dc2d631c3ba80af17e9c8c860f PatchThird Party Advisory
- https://github.com/libgd/libgd/pull/580 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/02/msg00014.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00003.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-14553
- https://usn.ubuntu.com/4316-1/ vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/4316-2/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-14553
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 11, 2020
Updated Aug 5, 2024
Reserved Jul 23, 2018
Link CVE-2018-14553
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-6462 Assigner mitre
Published Feb 11, 2020
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2018-6462