CVE-2006-4484: Buffer Overflow
Buffer overflow in the LWZReadByte function in ext/gd/libgd/gdgifin.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with inputcodesize greater than MAXLWZBITS, which triggers an overflow when initializing the table array.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2006-4484?
CVE-2006-4484 is classified as a high severity vulnerability due to the risk of remote code execution from a crafted GIF file.
How do I fix CVE-2006-4484?
To fix CVE-2006-4484, upgrade your GD library and PHP to versions higher than 5.1.5.
What specific versions of PHP are affected by CVE-2006-4484?
CVE-2006-4484 affects PHP versions 5.1.0 to 5.1.4.
What is the nature of the vulnerability in CVE-2006-4484?
The vulnerability in CVE-2006-4484 is a buffer overflow in the LWZReadByte_ function when processing GIF files.
Can CVE-2006-4484 be exploited remotely?
Yes, CVE-2006-4484 can be exploited remotely through maliciously crafted GIF files.