CVE-2019-6977

Updated: 2024-11-24 03:28:44.864996

Description:

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 6.8
CVSS Version 3.x HIGH 8.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 php 5.6 8.8 HIGH Needs Triage 2025-04-28 18:48:47
Debian 10 php 7.0 8.8 HIGH Needs Triage 2025-04-28 18:48:48
Debian 10 php 7.1 8.8 HIGH Needs Triage 2025-04-28 18:48:49
Debian 10 php 7.2 8.8 HIGH Needs Triage 2025-04-28 18:48:50
Debian 10 php 7.4 8.8 HIGH Needs Triage 2025-04-28 18:48:53
Debian 10 php 8.1 8.8 HIGH Needs Triage 2025-04-28 18:48:55
Debian 10 php 7.3 8.8 HIGH Needs Triage 2025-04-28 18:48:51
Debian 10 php 8.0 8.8 HIGH Needs Triage 2025-04-28 18:48:54
Debian 10 php 8.2 8.8 HIGH Needs Triage 2025-04-28 18:48:56
Debian 11 php 5.6 8.8 HIGH Needs Triage 2025-04-28 18:48:58
Total: 124