Description
The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1055-1 | libgd2 security update |
Debian DSA |
DSA-3938-1 | libgd2 security update |
EUVD |
EUVD-2017-16862 | The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information. |
Ubuntu USN |
USN-3389-1 | GD vulnerability |
Ubuntu USN |
USN-3389-2 | GD vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T16:19:29.486Z
Reserved: 2017-04-17T00:00:00.000Z
Link: CVE-2017-7890
No data.
Status : Modified
Published: 2017-08-02T19:29:00.897
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-7890
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN