CVE-2006-4484

Modified
Published: 31 Aug 2006, 21:00
Last modified:07 Aug 2024, 19:14

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
2.6 LOW
v2.0 (nvd)
EPSS Score
6.44% LOW
6% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

31 Aug 2006, 21:00
Published
Vulnerability first disclosed
07 Aug 2024, 19:14
Last Modified
Vulnerability information updated

Description

Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.

CVSS Metrics

  • v2.0LOWScore: 2.6AV:N/AC:H/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 6.44% Percentile: 91%

Affected Systems

  • UnknownPHP

    5.1.0 | 5.1.1 | 5.1.2 | 5.1.4

References (50)