CVE-2019-11038
Last modified
CVE-2019-11038 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.. EPSS estimates a 4.33% chance of exploitation in the next 30 days.
Description
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Libgd | Libgd | 2.2.5 | — |
| Php | Php | >= 7.1.0, < 7.1.30 | — |
| Php | Php | >= 7.2.0, < 7.2.19 | — |
| Php | Php | >= 7.3.0, < 7.3.6 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Canonical | Ubuntu Linux | 18.04 | — |
| Canonical | Ubuntu Linux | 19.10 | — |
| Debian | Debian Linux | 8.0 | — |
| Debian | Debian Linux | 9.0 | — |
| Fedoraproject | Fedora | 29 | — |
| Fedoraproject | Fedora | 30 | — |
| Fedoraproject | Fedora | 32 | — |
| Suse | Linux Enterprise Debuginfo | 11 | Sp4 |
| Opensuse | Leap | 15.1 | — |
| Suse | Linux Enterprise Desktop | 12 | Sp4 |
| Suse | Linux Enterprise Server | 12 | Sp4 |
| Suse | Linux Enterprise Software Development Kit | 12 | Sp4 |
| Suse | Linux Enterprise Workstation Extension | 12 | Sp4 |
| Redhat | Software Collections | 1.0 | — |
| Redhat | Enterprise Linux | 7.0 | — |
| Redhat | Enterprise Linux | 8.0 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3299Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929821Mailing List, Third Party Advisory
- https://bugs.php.net/bug.php?id=77973Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724149Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724432Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140118Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140120Exploit, Issue Tracking, Third Party Advisory
- https://github.com/libgd/libgd/issues/501Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00003.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/38Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4316-1/Third Party Advisory
- https://usn.ubuntu.com/4316-2/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4529Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3299Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929821Mailing List, Third Party Advisory
- https://bugs.php.net/bug.php?id=77973Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724149Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724432Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140118Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1140120Exploit, Issue Tracking, Third Party Advisory
- https://github.com/libgd/libgd/issues/501Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00003.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/38Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4316-1/Third Party Advisory
- https://usn.ubuntu.com/4316-2/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4529Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11038?
How severe is CVE-2019-11038?
How do I fix CVE-2019-11038?
Are you affected by CVE-2019-11038?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
