5.3
CVE-2019-11038
- EPSS 4.33%
- Veröffentlicht 19.06.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:20:25
- Erkennungen
Uninitialized read in gdImageCreateFromXbm
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 32
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Suse ≫ Linux Enterprise Desktop Version 12 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp5
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update sp4
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update sp5
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp4
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp5
Redhat ≫ Software Collections Version 1.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.33% | 0.899 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| PHP | 3.1 | 1.6 | 1.4 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
|
CWE-457 Use of Uninitialized Variable
The code uses a variable that has not been initialized, leading to unpredictable or unintended results.
CWE-908 Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
https://access.redhat.com/errata/RHSA-2019:2519
https://access.redhat.com/errata/RHSA-2019:3299
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/
https://seclists.org/bugtraq/2019/Sep/38
https://www.debian.org/security/2019/dsa-4529
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.html
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929821
https://bugs.php.net/bug.php?id=77973
https://bugzilla.redhat.com/show_bug.cgi?id=1724149
https://bugzilla.redhat.com/show_bug.cgi?id=1724432
https://bugzilla.suse.com/show_bug.cgi?id=1140118
https://bugzilla.suse.com/show_bug.cgi?id=1140120
https://github.com/libgd/libgd/issues/501
https://lists.debian.org/debian-lts-announce/2019/06/msg00003.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKSSWFR2WPMUOIB5EN5ZM252NNEPYUTG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WAZBVK6XNYEIN7RDQXESSD63QHXPLKWL/
https://usn.ubuntu.com/4316-1/
https://usn.ubuntu.com/4316-2/