CVE-2018-14553: Null Pointer Dereference
A flaw was found in gd as shipped with Fedora. Cloning a image with style "attached", triggers a NULL pointer dereference in 'gdImageClone' leading to denial of service.
Affected versions: gd-2.2.5 gd-2.2.4 gd-2.2.3 gd-2.2.2 gd-2.2.1 gd-2.2.0 gd-2.1.1 gd-2.1.0 gd-2.1.0-rc2
References:
https://bugzilla.redhat.com/showbug.cgi?id=1599032
Other sources
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-14553?
CVE-2018-14553 is a vulnerability in libgd that allows attackers to crash an application via a specific function call sequence.
How does CVE-2018-14553 impact PHP?
CVE-2018-14553 only affects PHP when it is linked with an external libgd (not bundled).
What is the severity level of CVE-2018-14553?
CVE-2018-14553 has a severity level of high.
How can CVE-2018-14553 be exploited?
CVE-2018-14553 can be exploited by attackers to crash an application by using a specific function call sequence.
What is the remedy for CVE-2018-14553?
The remedy for CVE-2018-14553 is to upgrade to libgd version 2.2.5-7.el8 or later.