The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | * | 5.4.32 (excluding) |
Php | Php | 5.5.0 (including) | 5.5.16 (excluding) |
Libgd2 | Ubuntu | lucid | * |
Libgd2 | Ubuntu | precise | * |
Libgd2 | Ubuntu | quantal | * |
Libgd2 | Ubuntu | saucy | * |
Libgd2 | Ubuntu | trusty | * |
Libgd2 | Ubuntu | upstream | * |
Libgd2 | Ubuntu | utopic | * |
Red Hat Enterprise Linux 5 | RedHat | php53-0:5.3.3-24.el5 | * |
Red Hat Enterprise Linux 6 | RedHat | php-0:5.3.3-27.el6_5.2 | * |
Red Hat Enterprise Linux 7 | RedHat | php-0:5.4.16-23.el7_0.1 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | RedHat | php54-php-0:5.4.16-22.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | RedHat | php55-php-0:5.5.6-13.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | RedHat | php54-php-0:5.4.16-22.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | RedHat | php55-php-0:5.5.6-13.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS | RedHat | php54-php-0:5.4.16-22.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS | RedHat | php55-php-0:5.5.6-13.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS | RedHat | php54-php-0:5.4.16-22.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS | RedHat | php55-php-0:5.5.6-13.el6 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 | RedHat | php54-php-0:5.4.16-22.el7 | * |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 | RedHat | php55-php-0:5.5.6-13.el7 | * |