Vulnerability Description
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | <= 5.6.32 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 14.04 |
Related Weaknesses (CWE)
References
- http://php.net/ChangeLog-5.phpRelease NotesVendor Advisory
- http://php.net/ChangeLog-7.phpRelease NotesVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1296Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519
- https://bugs.php.net/bug.php?id=75571PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/01/msg00022.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00028.htmlThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/201903-18Third Party Advisory
- https://usn.ubuntu.com/3755-1/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html
- http://php.net/ChangeLog-5.phpRelease NotesVendor Advisory
- http://php.net/ChangeLog-7.phpRelease NotesVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1296Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519
FAQ
What is CVE-2018-5711?
CVE-2018-5711 is a vulnerability with a CVSS score of 5.5 (MEDIUM). gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an inf...
How severe is CVE-2018-5711?
CVE-2018-5711 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5711?
Check the references section above for vendor advisories and patch information. Affected products include: Php Php, Debian Debian Linux, Canonical Ubuntu Linux.