CVE-2019-11038
Vulnerability Summary
Timeline
Description
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- v3.0•LOW•Score: 3.1CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 10.54%• Percentile: 93%
Techniques & Countermeasures
- CWE-908•Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
- CWE-457•Use of Uninitialized Variable
The code uses a variable that has not been initialized, leading to unpredictable or unintended results.
Affected Systems
- canonical•ubuntu_linux
14.04 | 16.04 | 18.04 | 19.10
- debian•debian_linux
8.0 | 9.0
- fedoraproject•fedora
29 | 30 | 32
- libgd•libgd
2.2.5
- opensuse•leap
15.1
- Unknown•PHP
7.1.x < 7.1.30 | 7.2.x < 7.2.19 | 7.3.x < 7.3.6
- Unknown•PHP
≥ 7.1.0, < 7.1.30 | ≥ 7.2.0, < 7.2.19 | ≥ 7.3.0, < 7.3.6
- redhat•enterprise_linux
7.0 | 8.0
- redhat•software_collections
1.0
- suse•linux_enterprise_debuginfo
11:sp4
- suse•linux_enterprise_desktop
12:sp4
- suse•linux_enterprise_server
12:sp4 | 12:sp5
- suse•linux_enterprise_software_development_kit
12:sp4 | 12:sp5
- suse•linux_enterprise_workstation_extension
12:sp4 | 12:sp5
References (18)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKSSWFR2WPMUOIB5EN5ZM252NNEPYUTG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WAZBVK6XNYEIN7RDQXESSD63QHXPLKWL/
- https://lists.debian.org/debian-lts-announce/2019/06/msg00003.html
- https://bugs.php.net/bug.php?id=77973
- https://github.com/libgd/libgd/issues/501
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929821
- https://bugzilla.suse.com/show_bug.cgi?id=1140118
- https://bugzilla.suse.com/show_bug.cgi?id=1140120
- https://bugzilla.redhat.com/show_bug.cgi?id=1724149
- https://bugzilla.redhat.com/show_bug.cgi?id=1724432
- https://access.redhat.com/errata/RHSA-2019:2519
- https://www.debian.org/security/2019/dsa-4529
- https://seclists.org/bugtraq/2019/Sep/38
- https://access.redhat.com/errata/RHSA-2019:3299
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/
- https://usn.ubuntu.com/4316-2/
- https://usn.ubuntu.com/4316-1/