5.3

CVE-2019-11038

Exploit

Uninitialized read in gdImageCreateFromXbm

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libgd ≫ Libgd Version 2.2.5
Php ≫ Php Version >= 7.1.0 < 7.1.30
Php ≫ Php Version >= 7.2.0 < 7.2.19
Php ≫ Php Version >= 7.3.0 < 7.3.6
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 32
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Opensuse ≫ Leap Version 15.1
Suse ≫ Linux Enterprise Desktop Version 12 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp5
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp4
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp5
Redhat ≫ Software Collections Version 1.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.33% 0.899
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
PHP 3.1 1.6 1.4
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
CWE-457 Use of Uninitialized Variable

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

https://access.redhat.com/errata/RHSA-2019:2519
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3299
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/
https://seclists.org/bugtraq/2019/Sep/38
Third Party Advisory
Mailing List
https://www.debian.org/security/2019/dsa-4529
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.html
Third Party Advisory
Mailing List
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929821
Third Party Advisory
Mailing List
https://bugs.php.net/bug.php?id=77973
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1724149
Third Party Advisory
Exploit
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1724432
Third Party Advisory
Exploit
Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=1140118
Third Party Advisory
Exploit
Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=1140120
Third Party Advisory
Exploit
Issue Tracking
https://github.com/libgd/libgd/issues/501
Third Party Advisory
Exploit
https://lists.debian.org/debian-lts-announce/2019/06/msg00003.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKSSWFR2WPMUOIB5EN5ZM252NNEPYUTG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WAZBVK6XNYEIN7RDQXESSD63QHXPLKWL/
https://usn.ubuntu.com/4316-1/
Third Party Advisory
https://usn.ubuntu.com/4316-2/
Third Party Advisory