Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | 5.1.0 (including) | 5.1.0 (including) |
Php | Php | 5.1.1 (including) | 5.1.1 (including) |
Php | Php | 5.1.2 (including) | 5.1.2 (including) |
Php | Php | 5.1.4 (including) | 5.1.4 (including) |
Red Hat Enterprise Linux 3 | RedHat | php-0:4.3.2-36.ent | * |
Red Hat Enterprise Linux 4 | RedHat | php-0:4.3.9-3.18 | * |
Red Hat Enterprise Linux 4 | RedHat | gd-0:2.0.28-5.4E.el4_6.1 | * |
Red Hat Enterprise Linux 5 | RedHat | gd-0:2.0.33-9.4.el5_1.1 | * |
Red Hat Web Application Stack for RHEL 4 | RedHat | php-0:5.1.4-1.el4s1.4 | * |
Php5 | Ubuntu | dapper | * |