Description
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1,
and the GD Graphics Library 2.x, does not properly verify a certain
colorsTotal structure member, which might allow remote attackers to conduct
buffer overflow or buffer over-read attacks via a crafted GD file, a
different vulnerability than CVE-2009-3293. NOTE: some of these details are
obtained from third party information.
Notes
| mdeslaur | PoC in php commit
php not affected - uses system libgd2 |
Updated: 2022-02-10 23:38:51 UTC (commit acb3d89ab51f1d5e5543fa993969c0eb13c71f04)