First published: Thu Feb 13 2014(Updated: )
A heap overflow vulnerability in PHP 5.5.0 and later was reported [1] in PHP's imagecrop() function. In code that used the imagecrop() function to crop untrusted images, this vulnerability could cause a crash of the script or, possibly, the execution of arbitrary code as the user running the PHP script. This has been corrected in PHP 5.5.9 [2]. [1] <a href="https://bugs.php.net/bug.php?id=66356">https://bugs.php.net/bug.php?id=66356</a> [2] <a href="http://git.php.net/?p=php-src.git;a=commitdiff;h=8f4a5373bb71590352fd934028d6dde5bc18530b">http://git.php.net/?p=php-src.git;a=commitdiff;h=8f4a5373bb71590352fd934028d6dde5bc18530b</a> External References: <a href="http://www.php.net/ChangeLog-5.php#5.5.9">http://www.php.net/ChangeLog-5.php#5.5.9</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP PHP | =5.5.0-alpha1 | |
PHP PHP | =5.5.0-alpha2 | |
PHP PHP | =5.5.0-alpha3 | |
PHP PHP | =5.5.0-alpha4 | |
PHP PHP | =5.5.0-alpha5 | |
PHP PHP | =5.5.0-alpha6 | |
PHP PHP | =5.5.0-beta1 | |
PHP PHP | =5.5.0-beta2 | |
PHP PHP | =5.5.0-beta3 | |
PHP PHP | =5.5.0-beta4 | |
PHP PHP | =5.5.0-rc1 | |
PHP PHP | =5.5.0-rc2 | |
PHP PHP | =5.5.1 | |
PHP PHP | =5.5.2 | |
PHP PHP | =5.5.3 | |
PHP PHP | =5.5.4 | |
PHP PHP | =5.5.5 | |
PHP PHP | =5.5.6 | |
PHP PHP | =5.5.7 | |
PHP PHP | =5.5.8 | |
redhat/php | <5.5.10 | 5.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.