CVE-2013-7456: High severity Libgd Libgd vulnerability
gdinterpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted image that is mishandled by the imagescale function.
Other sources
Fixed bug (imagescale out-of-bounds read). (CVE-2013-7456)
— PHP
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7456?
CVE-2013-7456 is classified as a denial of service vulnerability due to an out-of-bounds read.
How do I fix CVE-2013-7456?
To remediate CVE-2013-7456, upgrade the GD Graphics Library to version 2.1.1 or later and ensure PHP is updated to version 5.5.36 or higher, or 5.6.22 or higher, or 7.0.7 or higher.
What versions are affected by CVE-2013-7456?
CVE-2013-7456 affects GD Graphics Library versions prior to 2.1.1 and PHP versions prior to 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7.
Can CVE-2013-7456 lead to an exploit?
CVE-2013-7456 could potentially be exploited by attackers to cause a denial of service through crafted images.
Which software should I check for CVE-2013-7456 vulnerabilities?
Check if you are using vulnerable versions of the GD Graphics Library or PHP that are affected by CVE-2013-7456.