Uninitialized read in gdImageCreateFromXbm
Published Jun 18, 2019
5.3
MEDIUMCVSS 3.1
EPSS 4.33%
Description
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.
Affected products
-
- Version 7.1.x < 7.1.30StatusaffectedConstraints-
- Version 7.2.x < 7.2.19StatusaffectedConstraints-
- Version 7.3.x < 7.3.6StatusaffectedConstraints-
- Version
Configuration 1
Configuration 2
- 14.04
- 16.04
- 18.04
- 19.10
Configuration 3
- 8.0
- 9.0
Configuration 4
- 29
- 30
- 32
Configuration 5
- 11
- 15.1
- 12
- 12
- 12
- 12
- 12
- 12
- 12
Configuration 6
- 1.0
- 7.0
- 8.0
No data.
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Enterprise Linux 5
gd
Out of support scope
Red Hat Enterprise Linux 5
php
Out of support scope
Red Hat Enterprise Linux 5
php53
Out of support scope
Red Hat Enterprise Linux 6
gd
Out of support scope
Red Hat Enterprise Linux 6
php
Out of support scope
Red Hat Enterprise Linux 7
gd
Fix deferred
Red Hat Enterprise Linux 7
php
Fix deferred
Red Hat Enterprise Linux 8
gd
Fix deferred
Red Hat Enterprise Linux 8
php:7.2/php
Not affected
Red Hat Software Collections
rh-php70-php
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Enterprise Linux 5 | gd | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | php53 | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | gd | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | gd | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | php | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gd | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | php:7.2/php | Not affected | n/a |
| Red Hat Software Collections | rh-php70-php | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In order to successfully exploit this vulnerability, the following prerequisites must be fulfilled: * An attacker needs to supply a maliciously crafted XBM image designed to exploit the uninitialized variable in the gdImageCreateFromXbm() function. * The application or service must accept and process XBM images using the vulnerable gdImageCreateFromXbm() function. * User interaction is required to process the malicious XBM file. It's important to note that successful exploitation requires that the application processes untrusted XBM image data using the vulnerable function. As this is not common practice, RH ProdSec has set the Impact of this vulnerability to "Low"
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (56 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 4.33% (0.04332) | 90.90th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.33% (0.04332) | 89.90th | v5 (v2026.06.15) |
| Jun 14, 2026 | 9.05% (0.09055) | 92.85th | v4 (v2025.03.14) |
| Mar 4, 2026 | 10.72% (0.10719) | 93.19th | v4 (v2025.03.14) |
| Mar 1, 2026 | 3.64% (0.03639) | 87.66th | v4 (v2025.03.14) |
| Feb 4, 2026 | 10.72% (0.10719) | 93.14th | v4 (v2025.03.14) |
| Feb 1, 2026 | 3.64% (0.03639) | 87.59th | v4 (v2025.03.14) |
| Jan 4, 2026 | 10.72% (0.10719) | 93.08th | v4 (v2025.03.14) |
| Jan 1, 2026 | 3.64% (0.03639) | 87.55th | v4 (v2025.03.14) |
| Dec 28, 2025 | 10.72% (0.10719) | 93.08th | v4 (v2025.03.14) |
| Dec 27, 2025 | 6.70% (0.06703) | 90.98th | v4 (v2025.03.14) |
| Dec 13, 2025 | 10.72% (0.10719) | 93.06th | v4 (v2025.03.14) |
| Dec 10, 2025 | 12.18% (0.12180) | 93.57th | v4 (v2025.03.14) |
| Dec 4, 2025 | 10.50% (0.10498) | 92.97th | v4 (v2025.03.14) |
| Dec 1, 2025 | 3.61% (0.03613) | 87.42th | v4 (v2025.03.14) |
| Nov 29, 2025 | 10.50% (0.10498) | 92.96th | v4 (v2025.03.14) |
| Nov 21, 2025 | 8.29% (0.08292) | 91.89th | v4 (v2025.03.14) |
| Nov 18, 2025 | 4.42% (0.04417) | 87.91th | v4 (v2025.03.14) |
| Nov 4, 2025 | 8.29% (0.08292) | 91.86th | v4 (v2025.03.14) |
| Nov 1, 2025 | 2.79% (0.02794) | 85.62th | v4 (v2025.03.14) |
| Oct 28, 2025 | 8.29% (0.08292) | 91.85th | v4 (v2025.03.14) |
| Oct 27, 2025 | 6.01% (0.06012) | 90.30th | v4 (v2025.03.14) |
| Oct 4, 2025 | 8.29% (0.08292) | 91.91th | v4 (v2025.03.14) |
| Oct 1, 2025 | 2.79% (0.02794) | 85.61th | v4 (v2025.03.14) |
| Sep 5, 2025 | 6.01% (0.06012) | 90.35th | v4 (v2025.03.14) |
| Sep 1, 2025 | 1.72% (0.01724) | 81.75th | v4 (v2025.03.14) |
| Aug 6, 2025 | 6.01% (0.06012) | 90.34th | v4 (v2025.03.14) |
| Aug 1, 2025 | 1.72% (0.01724) | 81.73th | v4 (v2025.03.14) |
| Jul 30, 2025 | 6.01% (0.06012) | 90.33th | v4 (v2025.03.14) |
| Jul 13, 2025 | 8.29% (0.08292) | 91.83th | v4 (v2025.03.14) |
| Jul 12, 2025 | 10.50% (0.10498) | 92.88th | v4 (v2025.03.14) |
| Jul 4, 2025 | 9.21% (0.09212) | 92.33th | v4 (v2025.03.14) |
| Jul 1, 2025 | 3.08% (0.03082) | 86.26th | v4 (v2025.03.14) |
| Jun 5, 2025 | 9.21% (0.09212) | 92.27th | v4 (v2025.03.14) |
| Jun 1, 2025 | 3.08% (0.03082) | 86.20th | v4 (v2025.03.14) |
| May 4, 2025 | 10.05% (0.10050) | 92.62th | v4 (v2025.03.14) |
| May 1, 2025 | 3.60% (0.03604) | 87.17th | v4 (v2025.03.14) |
| Apr 6, 2025 | 10.05% (0.10050) | 92.36th | v4 (v2025.03.14) |
| Apr 5, 2025 | 3.60% (0.03604) | 86.72th | v4 (v2025.03.14) |
| Mar 30, 2025 | 10.05% (0.10050) | 92.34th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.40% (0.08396) | 86.93th | v4 (v2025.03.14) |
| Mar 17, 2025 | 10.05% (0.10050) | 92.50th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.32% (0.00322) | 71.51th | v3 (v2023.03.01) |
| May 21, 2024 | 0.38% (0.00381) | 72.92th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.29% (0.00289) | 68.08th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.29% (0.00289) | 65.47th | v3 (v2023.03.01) |
| Oct 12, 2023 | 0.22% (0.00219) | 59.53th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.20% (0.00204) | 57.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00238) | 60.04th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.44% (0.23437) | 94.77th | v2 (v2022.01.01) |
| Feb 3, 2022 | 15.32% (0.15322) | 90.03th | v1 |
| Jan 6, 2022 | 15.32% (0.15322) | 89.91th | v1 |
| Jan 5, 2022 | 3.88% (0.03876) | 83.52th | v5 (v2026.06.15) |
| Apr 14, 2021 | 3.88% (0.03876) | 0.00th | v1 |
References (21)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3299 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11038 Vendor Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929821 x_refsource_CONFIRMMailing ListThird Party Advisory
- https://bugs.php.net/bug.php?id=77973 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724149 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724432 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140118 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140120 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://github.com/libgd/libgd/issues/501 x_refsource_CONFIRMExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00003.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKSSWFR2WPMUOIB5EN5ZM252NNEPYUTG/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WAZBVK6XNYEIN7RDQXESSD63QHXPLKWL/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-11038
- https://seclists.org/bugtraq/2019/Sep/38 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://usn.ubuntu.com/4316-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4316-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11038
- https://www.debian.org/security/2019/dsa-4529 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.