CVE-2019-6977
HIGHGD Graphics Library <2.2.5 - Buffer Overflow
Title source: llmDescription
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.
Exploits (1)
References (19)
Scores
CVSS v3
8.8
EPSS
0.8630
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (10)
canonical/ubuntu_linux
14.04
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
18.04
canonical/ubuntu_linux
18.10
debian/debian_linux
8.0
debian/debian_linux
9.0
libgd/libgd
2.2.5
netapp/storage_automation_store
php/php
7.3.0
php/php
< 5.6.40
Published
Jan 27, 2019
Tracked Since
Feb 18, 2026