CVE-2014-2497
published 2014-03-21CVE-2014-2497: The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
22.32%
97.4th percentile
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libgd2 | < libgd2 2.1.0-4 (bookworm) | libgd2 2.1.0-4 (bookworm) |
| oracle | solaris | — | — |
| php | php | < 5.4.32 | 5.4.32 |
| php | php | >= 5.5.0 < 5.5.16 | 5.5.16 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GD library vulnerabilities
vendor_ubuntu·2016-05-31·CVSS 4.3
CVE-2014-2497 [MEDIUM] GD library vulnerabilities
Title: GD library vulnerabilities
Summary: The GD library could be made to crash or run programs if it processed a
specially crafted image file.
It was discovered that the GD library incorrectly handled certain color
tables in XPM images. If a user or automated system were tricked into
processing a specially crafted XPM image, an attacker could cause a denial
of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2014-2497)
It was discovered that the GD library incorrectly handled certain malformed
GIF images. If a user or automated system were tricked into processing a
specially crafted GIF image, an attacker could cause a denial of service.
This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2014-9709)
It was discovered that the GD library i
Red Hat
gd: NULL pointer dereference in gdImageCreateFromXpm()
vendor_redhat·2014-03-13·CVSS 4.3
CVE-2014-2497 [MEDIUM] CWE-476 gd: NULL pointer dereference in gdImageCreateFromXpm()
gd: NULL pointer dereference in gdImageCreateFromXpm()
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
A NULL pointer dereference flaw was found in the gdImageCreateFromXpm() function of PHP's gd extension. A remote attacker could use this flaw to crash a PHP application using gd via a specially crafted X PixMap (XPM) file.
Package: gd (Red Hat Enterprise Linux 5) - Will not fix
Package: libwmf (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: gd (Red Hat Enterprise Linux 6) - Will not fix
Package: libwmf (Red Hat Enterprise Linux 6) - Not a
Debian
CVE-2014-2497: libgd2 - The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and...
vendor_debian·2014·CVSS 4.3
CVE-2014-2497 [MEDIUM] CVE-2014-2497: libgd2 - The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and...
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
Scope: local
bookworm: resolved (fixed in 2.1.0-4)
bullseye: resolved (fixed in 2.1.0-4)
forky: resolved (fixed in 2.1.0-4)
sid: resolved (fixed in 2.1.0-4)
trixie: resolved (fixed in 2.1.0-4)
Apple
CVE-2014-2497: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 4.3
CVE-2014-2497 [MEDIUM] CVE-2014-2497: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2014-2497
Component: CVE-2014-2497
GHSA
GHSA-7x54-3j5f-jcr9: The gdImageCreateFromXpm function in gdxpm
ghsa_unreviewed·2022-05-17
CVE-2014-2497 [MEDIUM] CWE-476 GHSA-7x54-3j5f-jcr9: The gdImageCreateFromXpm function in gdxpm
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
OSV
libgd2 vulnerabilities
osv·2016-05-31·CVSS 4.3
CVE-2014-2497 [MEDIUM] libgd2 vulnerabilities
libgd2 vulnerabilities
It was discovered that the GD library incorrectly handled certain color
tables in XPM images. If a user or automated system were tricked into
processing a specially crafted XPM image, an attacker could cause a denial
of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2014-2497)
It was discovered that the GD library incorrectly handled certain malformed
GIF images. If a user or automated system were tricked into processing a
specially crafted GIF image, an attacker could cause a denial of service.
This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2014-9709)
It was discovered that the GD library incorrectly handled memory when using
gdImageFillToBorder(). A remote attacker could possibly use this issue to
cause a deni
OSV
CVE-2014-2497: The gdImageCreateFromXpm function in gdxpm
osv·2014-03-21·CVSS 4.3
CVE-2014-2497 [MEDIUM] CVE-2014-2497: The gdImageCreateFromXpm function in gdxpm
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2497 gd: NULL pointer dereference in gdImageCreateFromXpm() [fedora-all]
bugzilla·2014-03-24·CVSS 4.3
CVE-2014-2497 [MEDIUM] CVE-2014-2497 gd: NULL pointer dereference in gdImageCreateFromXpm() [fedora-all]
CVE-2014-2497 gd: NULL pointer dereference in gdImageCreateFromXpm() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
CVE-2014-2497 php: gd: NULL pointer dereference in gdImageCreateFromXpm() [fedora-all]
bugzilla·2014-03-24·CVSS 4.3
CVE-2014-2497 [MEDIUM] CVE-2014-2497 php: gd: NULL pointer dereference in gdImageCreateFromXpm() [fedora-all]
CVE-2014-2497 php: gd: NULL pointer dereference in gdImageCreateFromXpm() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2014-2497 gd: NULL pointer dereference in gdImageCreateFromXpm()
bugzilla·2014-03-14·CVSS 4.3
CVE-2014-2497 [MEDIUM] CVE-2014-2497 gd: NULL pointer dereference in gdImageCreateFromXpm()
CVE-2014-2497 gd: NULL pointer dereference in gdImageCreateFromXpm()
It was reported [1] that the gdImageCreateFromXpm() function in libgd could dereference a NULL pointer, noting:
"The call to strlen() parses image.colorTable[i].c_color which is initialised as NULL if the particular color mapping uses a different key (such as monochrome/monovisual)."
This was reported against PHP, which includes an embedded copy of the gd library. CVE-2014-2497 was assigned to this issue [2].
[1] https://bugs.php.net/bug.php?id=66901
[2] http://seclists.org/oss-sec/2014/q1/580
Discussion:
Note that the PHP bug includes a reproducer, but it does not seem to work with the versions I've tried (it notes version 5.4.17, I tried with 5.4.25 and 5.3.3):
$ echo ''|php
Warning: imagecreatefromxpm(): 'monoc
http://advisories.mageia.org/MGASA-2014-0288.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-07/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1326.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1327.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/59061http://secunia.com/advisories/59418http://secunia.com/advisories/59496http://secunia.com/advisories/59652http://www.debian.org/security/2015/dsa-3215http://www.mandriva.com/security/advisories?name=MDVSA-2015:153http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/66233http://www.ubuntu.com/usn/USN-2987-1https://bugs.php.net/bug.php?id=66901https://bugzilla.redhat.com/show_bug.cgi?id=1076676https://security.gentoo.org/glsa/201607-04https://support.apple.com/HT204659http://advisories.mageia.org/MGASA-2014-0288.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-07/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-07/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1326.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1327.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1765.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1766.htmlhttp://secunia.com/advisories/59061http://secunia.com/advisories/59418http://secunia.com/advisories/59496http://secunia.com/advisories/59652http://www.debian.org/security/2015/dsa-3215http://www.mandriva.com/security/advisories?name=MDVSA-2015:153http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/66233http://www.ubuntu.com/usn/USN-2987-1https://bugs.php.net/bug.php?id=66901https://bugzilla.redhat.com/show_bug.cgi?id=1076676https://security.gentoo.org/glsa/201607-04https://support.apple.com/HT204659
2014-03-21
Published