Severity
5.3MEDIUM
EPSS
10.5%
top 6.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19
Latest updateMay 24

Description

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages11 packages

Debianlibgd2< 2.2.5-5.2+3
NVDlibgd/libgd2.2.5
NVDphp/php7.1.07.1.30+2
CVEListV5php_group/php7.1.x < 7.1.30, 7.2.x < 7.2.19, 7.3.x < 7.3.6+2

Also affects: Debian Linux 8.0, 9.0, Fedora 29, 30, 32, Ubuntu Linux 14.04, 16.04, 18.04, 19.10, Enterprise Linux 7.0, 8.0

🔴Vulnerability Details

5
GHSA
GHSA-8v67-h8jw-j3r2: When using gdImageCreateFromXbm() function of gd extension in versions 72022-05-24
OSV
libgd2 vulnerabilities2020-04-02
OSV
libgd2 vulnerabilities2020-04-02
OSV
CVE-2019-11038: When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 22019-06-19
CVEList
Uninitialized read in gdImageCreateFromXbm2019-06-18

📋Vendor Advisories

4
Ubuntu
GD Graphics Library vulnerabilities2020-04-02
Ubuntu
GD Graphics Library vulnerabilities2020-04-02
Red Hat
gd: Information disclosure in gdImageCreateFromXbm()2019-06-18
Debian
CVE-2019-11038: libgd2 - When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka L...2019

💬Community

4
HackerOne
Uninitialized read in gdImageCreateFromXbm2020-10-10
Bugzilla
CVE-2019-11038 gd: Information disclosure in gdImageCreateFromXbm() [fedora-all]2019-06-27
Bugzilla
CVE-2019-11038 CVE-2019-11039 CVE-2019-11040 php: various flaws [fedora-all]2019-06-26
Bugzilla
CVE-2019-11038 gd: Information disclosure in gdImageCreateFromXbm()2019-06-26