// For flags

CVE-2008-3658

php: buffer overflow in the imageloadfont function in gd extension

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

Un desbordamiento de búfer en la función imageloadfont en el archivo ext/gd/gd.c en PHP versiones 4.4.x anteriores a 4.4.9 y PHP versiones 5.2 anteriores a 5.2.6-r6, permite a los atacantes dependiendo del contexto causar una denegación de servicio (bloqueo) y posiblemente ejecutar código arbitrario por medio de un archivo de fuente diseñado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-08-12 CVE Reserved
  • 2008-08-15 CVE Published
  • 2024-03-31 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (42)
URL Tag Source
http://bugs.gentoo.org/show_bug.cgi?id=234102 X_refsource_confirm
http://osvdb.org/47484 Vdb Entry
http://secunia.com/advisories/31982 Third Party Advisory
http://secunia.com/advisories/32148 Third Party Advisory
http://secunia.com/advisories/32316 Third Party Advisory
http://secunia.com/advisories/32746 Third Party Advisory
http://secunia.com/advisories/32884 Third Party Advisory
http://secunia.com/advisories/33797 Third Party Advisory
http://secunia.com/advisories/35074 Third Party Advisory
http://secunia.com/advisories/35306 Third Party Advisory
http://support.apple.com/kb/HT3549 X_refsource_confirm
http://wiki.rpath.com/Advisories:rPSA-2009-0035 X_refsource_confirm
http://www.openwall.com/lists/oss-security/2008/08/08/2 Mailing List
http://www.openwall.com/lists/oss-security/2008/08/13/8 Mailing List
http://www.php.net/archive/2008.php#id2008-08-07-1 X_refsource_confirm
http://www.securityfocus.com/archive/1/501376/100/0/threaded Mailing List
http://www.securityfocus.com/bid/30649 Vdb Entry
http://www.us-cert.gov/cas/techalerts/TA09-133A.html Third Party Advisory
http://www.vupen.com/english/advisories/2008/2336 Vdb Entry
http://www.vupen.com/english/advisories/2008/3275 Vdb Entry
http://www.vupen.com/english/advisories/2009/0320 Vdb Entry
http://www.vupen.com/english/advisories/2009/1297 Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44401 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9724 Signature
URL Date SRC
http://news.php.net/php.cvs/51219 2024-08-07
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.0
Search vendor "Php" for product "Php" and version "4.4.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.1
Search vendor "Php" for product "Php" and version "4.4.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.2
Search vendor "Php" for product "Php" and version "4.4.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.3
Search vendor "Php" for product "Php" and version "4.4.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.4
Search vendor "Php" for product "Php" and version "4.4.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.5
Search vendor "Php" for product "Php" and version "4.4.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.6
Search vendor "Php" for product "Php" and version "4.4.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.7
Search vendor "Php" for product "Php" and version "4.4.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.8
Search vendor "Php" for product "Php" and version "4.4.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.0
Search vendor "Php" for product "Php" and version "5.2.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.1
Search vendor "Php" for product "Php" and version "5.2.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.2
Search vendor "Php" for product "Php" and version "5.2.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.3
Search vendor "Php" for product "Php" and version "5.2.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.4
Search vendor "Php" for product "Php" and version "5.2.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.5
Search vendor "Php" for product "Php" and version "5.2.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.6
Search vendor "Php" for product "Php" and version "5.2.6"
-
Affected