CVE-2018-5711
gd: Infinite loop in gdImageCreateFromGifCtx() in gd_gif_in.c
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.
gd_gif_in.c en GD Graphics Library (también conocida como libgd), tal y como se emplea en PHP en versiones anteriores a la 5.6.33, versiones 7.0.x anteriores a la 7.0.27, versiones 7.1.x anteriores a la 7.1.13 y versiones 7.2.x anteriores a la 7.2.1, tiene un error en la propiedad signedness de un número entero que conduce a un bucle infinito mediante un archivo GIF manipulado, tal y como demuestra una llamada a las funciones de PHP imagecreatefromgif o imagecreatefromstring. Esto se relaciona con GetCode_ y gdImageCreateFromGifCtx.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-16 CVE Reserved
- 2018-01-16 CVE Published
- 2018-02-01 First Exploit
- 2024-03-23 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-681: Incorrect Conversion between Numeric Types
- CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2018/01/msg00022.html | Mailing List | |
https://lists.debian.org/debian-lts-announce/2019/01/msg00028.html | Mailing List | |
https://www.oracle.com/security-alerts/cpuapr2020.html | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://github.com/huzhenghui/Test-7-2-0-PHP-CVE-2018-5711 | 2018-02-01 | |
https://github.com/huzhenghui/Test-7-2-1-PHP-CVE-2018-5711 | 2018-02-01 |
URL | Date | SRC |
---|---|---|
https://bugs.php.net/bug.php?id=75571 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
http://php.net/ChangeLog-5.php | 2023-11-07 | |
http://php.net/ChangeLog-7.php | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:1296 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2019:2519 | 2023-11-07 | |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6 | 2023-11-07 | |
https://security.gentoo.org/glsa/201903-18 | 2023-11-07 | |
https://usn.ubuntu.com/3755-1 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2018-5711 | 2019-08-19 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1535246 | 2019-08-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | <= 5.6.32 Search vendor "Php" for product "Php" and version " <= 5.6.32" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | >= 7.0.0 <= 7.0.26 Search vendor "Php" for product "Php" and version " >= 7.0.0 <= 7.0.26" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | > 7.1.0 <= 7.1.12 Search vendor "Php" for product "Php" and version " > 7.1.0 <= 7.1.12" | - |
Affected
| ||||||
Php Search vendor "Php" | Php Search vendor "Php" for product "Php" | 7.2.0 Search vendor "Php" for product "Php" and version "7.2.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 14.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "14.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 18.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "18.04" | lts |
Affected
|