First published: Fri Dec 26 2008(Updated: )
Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP | =5.1.5 | |
PHP | =5.1.2 | |
PHP | =5.1.1 | |
PHP | =5.0.0-beta1 | |
PHP | =5.1.6 | |
PHP | =5.0-rc1 | |
PHP | =5.2.7 | |
PHP | =5.2.2 | |
PHP | =5.0.5 | |
PHP | =5.0.1 | |
PHP | =5.1.4 | |
PHP | =5.2.5 | |
PHP | =5.0.4 | |
PHP | <=5.2.8 | |
PHP | =5.0-rc3 | |
PHP | =5.2.6 | |
PHP | =5.0.0-rc2 | |
PHP | =5.2.3 | |
PHP | =5.0.3 | |
PHP | =5.1.0 | |
PHP | =5.0.0-rc3 | |
PHP | =5.2.0 | |
PHP | =5.0-rc2 | |
PHP | =5.2.4 | |
PHP | =5.0.0-beta3 | |
PHP | =5.1.3 | |
PHP | =5.0.0-rc1 | |
PHP | =5.0.2 | |
PHP | =5.2.1 | |
PHP | =5.0.0-beta4 | |
PHP | =5 | |
PHP | =5.0.0 | |
PHP | =5.0.0-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5498 has been classified as a vulnerability with medium severity due to its potential to expose sensitive information.
To mitigate CVE-2008-5498, it is recommended to upgrade your PHP version to 5.2.9 or later.
CVE-2008-5498 affects various versions of PHP including 5.1.0 to 5.2.8 and certain beta and release candidates.
Exploiting CVE-2008-5498 may allow an attacker to read arbitrary memory locations, potentially revealing sensitive data.
While older versions of PHP are no longer in widespread use, CVE-2008-5498 remains a concern for anyone using those vulnerable versions.