CVE Vulnerabilities

CVE-2013-7226

Published: Feb 18, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an imagecrop function call with a large x dimension value, leading to a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Php Php 5.5.0-alpha1 (including) 5.5.0-alpha1 (including)
Php Php 5.5.0-alpha2 (including) 5.5.0-alpha2 (including)
Php Php 5.5.0-alpha3 (including) 5.5.0-alpha3 (including)
Php Php 5.5.0-alpha4 (including) 5.5.0-alpha4 (including)
Php Php 5.5.0-alpha5 (including) 5.5.0-alpha5 (including)
Php Php 5.5.0-alpha6 (including) 5.5.0-alpha6 (including)
Php Php 5.5.0-beta1 (including) 5.5.0-beta1 (including)
Php Php 5.5.0-beta2 (including) 5.5.0-beta2 (including)
Php Php 5.5.0-beta3 (including) 5.5.0-beta3 (including)
Php Php 5.5.0-beta4 (including) 5.5.0-beta4 (including)
Php Php 5.5.0-rc1 (including) 5.5.0-rc1 (including)
Php Php 5.5.0-rc2 (including) 5.5.0-rc2 (including)
Php Php 5.5.1 (including) 5.5.1 (including)
Php Php 5.5.2 (including) 5.5.2 (including)
Php Php 5.5.3 (including) 5.5.3 (including)
Php Php 5.5.4 (including) 5.5.4 (including)
Php Php 5.5.5 (including) 5.5.5 (including)
Php Php 5.5.6 (including) 5.5.6 (including)
Php Php 5.5.7 (including) 5.5.7 (including)
Php Php 5.5.8 (including) 5.5.8 (including)
Php5 Ubuntu saucy *
Php5 Ubuntu upstream *

References