CVE-2009-3546: Buffer Overflow
The gdGetColors function in gdgd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3546?
CVE-2009-3546 has a medium severity rating due to the potential for buffer overflow or buffer over-read attacks.
How do I fix CVE-2009-3546?
To fix CVE-2009-3546, upgrade to PHP version 5.3.1 or later and ensure that you are using the latest version of the GD Graphics Library.
Which software versions are affected by CVE-2009-3546?
CVE-2009-3546 affects PHP versions 5.2.11 and 5.3.x prior to 5.3.1, as well as multiple versions of the GD Graphics Library.
What type of attacks can CVE-2009-3546 enable?
CVE-2009-3546 could enable remote attackers to conduct buffer overflow or buffer over-read attacks via crafted GD files.
Is CVE-2009-3546 still a threat today?
CVE-2009-3546 is considered a historical vulnerability but may still pose a threat if outdated software versions are in use.