← Back

CVE-2019-11038

nvd nist
Published: Jun 19, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.

Affected (25)

Products: Libgd: Libgd · Php: Php · Canonical: Ubuntu Linux · +5 more
Show all products
1 product
Libgd
1 product
Php
1 product
Ubuntu Linux
1 product
Debian Linux
1 product
Fedora
1 product
Leap
5 products
Linux Enterprise Debuginfo
Linux Enterprise Desktop
Linux Enterprise Server
2 products
Enterprise Linux
Software Collections
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.2.5
Php
From 7.1.0 to 7.1.30
From 7.2.0 to 7.2.19
From 7.3.0 to 7.3.6
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 18.04
Version 19.10
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 29
Version 30
Version 32
Configuration E
9 vulnerable
Configuration F
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 7.0
Version 8.0
Version 1.0

References (36)

Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Vendor Advisory
Source: security@php.net
ExploitIssue TrackingThird Party Advisory
Source: security@php.net
ExploitIssue TrackingThird Party Advisory
Source: security@php.net
ExploitIssue TrackingThird Party Advisory
Source: security@php.net
ExploitIssue TrackingThird Party Advisory
Source: security@php.net
ExploitThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.