CVE Vulnerabilities

CVE-2013-7328

Published: Feb 18, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allow remote attackers to cause a denial of service (application crash) or obtain sensitive information via an imagecrop function call with a negative value for the (1) x or (2) y dimension, a different vulnerability than CVE-2013-7226.

Affected Software

Name Vendor Start Version End Version
Php Php 5.5.0 (including) 5.5.0 (including)
Php Php 5.5.0-alpha1 (including) 5.5.0-alpha1 (including)
Php Php 5.5.0-alpha2 (including) 5.5.0-alpha2 (including)
Php Php 5.5.0-alpha3 (including) 5.5.0-alpha3 (including)
Php Php 5.5.0-alpha4 (including) 5.5.0-alpha4 (including)
Php Php 5.5.0-alpha5 (including) 5.5.0-alpha5 (including)
Php Php 5.5.0-alpha6 (including) 5.5.0-alpha6 (including)
Php Php 5.5.0-beta1 (including) 5.5.0-beta1 (including)
Php Php 5.5.0-beta2 (including) 5.5.0-beta2 (including)
Php Php 5.5.0-beta3 (including) 5.5.0-beta3 (including)
Php Php 5.5.0-beta4 (including) 5.5.0-beta4 (including)
Php Php 5.5.0-rc1 (including) 5.5.0-rc1 (including)
Php Php 5.5.0-rc2 (including) 5.5.0-rc2 (including)
Php Php 5.5.1 (including) 5.5.1 (including)
Php Php 5.5.2 (including) 5.5.2 (including)
Php Php 5.5.3 (including) 5.5.3 (including)
Php Php 5.5.4 (including) 5.5.4 (including)
Php Php 5.5.5 (including) 5.5.5 (including)
Php Php 5.5.6 (including) 5.5.6 (including)
Php Php 5.5.7 (including) 5.5.7 (including)
Php Php 5.5.8 (including) 5.5.8 (including)
Php5 Ubuntu saucy *
Php5 Ubuntu upstream *

References