Wind River Support Network

HomeDefectsLIN8-8639
Fixed

LIN8-8639 : Security Advisory - libgd&php - CVE-2018-5711

Created: Jan 30, 2018    Updated: Dec 3, 2018
Resolved Date: Mar 15, 2018
Found In Version: 8.0.0.24
Fix Version: 8.0.0.26
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.

https://nvd.nist.gov/vuln/detail/CVE-2018-5711

Other Downloads


CVEs


Live chat
Online