4.3

CVE-2014-2497

Exploit
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version < 5.4.32
Php ≫ Php Version >= 5.5.0 < 5.5.16
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 15.10
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware
Redhat ≫ Enterprise Linux Eus Version 6.5
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Oracle ≫ Solaris Version 11.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.32% 0.974
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
Third Party Advisory
http://secunia.com/advisories/59652
Not Applicable
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
Broken Link
Mailing List
http://rhn.redhat.com/errata/RHSA-2014-1765.html
Third Party Advisory
https://support.apple.com/HT204659
Third Party Advisory
http://advisories.mageia.org/MGASA-2014-0288.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00001.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2014-1326.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1327.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-1766.html
Third Party Advisory
http://secunia.com/advisories/59061
Not Applicable
http://secunia.com/advisories/59418
Not Applicable
http://secunia.com/advisories/59496
Not Applicable
http://www.debian.org/security/2015/dsa-3215
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2015:153
Broken Link
http://www.securityfocus.com/bid/66233
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-2987-1
Third Party Advisory
https://bugs.php.net/bug.php?id=66901
Patch
Vendor Advisory
Exploit
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1076676
Patch
Third Party Advisory
Issue Tracking
https://security.gentoo.org/glsa/201607-04
Third Party Advisory