Back

MEDIUM

gd: Infinite loop in gdImageCreateFromGifCtx() in gd_gif_in.c

Published Jan 16, 2018

Description

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as low severity because it causes an infinite loop, resulting in a denial of service, while it can exhaust server resources and impact availability, it does not pose a threat to system security or integrity.

Metrics

Weaknesses (2)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 16, 2018
Updated Aug 5, 2024
Reserved Jan 16, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 25, 2017