MEDIUM · 5.3

CVE-2019-11038

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3....

Vulnerability Description

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LibgdLibgd2.2.5
PhpPhp>= 7.1.0, < 7.1.30
CanonicalUbuntu Linux14.04
DebianDebian Linux8.0
FedoraprojectFedora29
SuseLinux Enterprise Debuginfo11
OpensuseLeap15.1
SuseLinux Enterprise Desktop12
SuseLinux Enterprise Server12
SuseLinux Enterprise Software Development Kit12
SuseLinux Enterprise Workstation Extension12
RedhatSoftware Collections1.0
RedhatEnterprise Linux7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-11038?

CVE-2019-11038 is a vulnerability with a CVSS score of 5.3 (MEDIUM). When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3....

How severe is CVE-2019-11038?

CVE-2019-11038 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-11038?

Check the references section above for vendor advisories and patch information. Affected products include: Libgd Libgd, Php Php, Canonical Ubuntu Linux, Debian Debian Linux, Fedoraproject Fedora.