CVE-2009-3546

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libgd:gd_graphics_library:2.0.33:*:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.34:*:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.34:rc1:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.34:rc2:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.35:*:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.35:rc1:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.35:rc2:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.35:rc3:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.35:rc4:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.35:rc5:*:*:*:*:*:*
cpe:2.3:a:libgd:gd_graphics_library:2.0.36:rc1:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:php:php:5.2.11:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.0:*:*:*:*:*:*:*

History

13 Feb 2023, 02:20

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0003', 'name': 'https://access.redhat.com/errata/RHSA-2010:0003', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=529213', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=529213', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2009-3546', 'name': 'https://access.redhat.com/security/cve/CVE-2009-3546', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0040', 'name': 'https://access.redhat.com/errata/RHSA-2010:0040', 'tags': [], 'refsource': 'MISC'}
Summary CVE-2009-3546 gd: insufficient input validation in _gdGetColors() The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

02 Feb 2023, 17:16

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0003 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=529213 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2009-3546 -
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0040 -
Summary The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information. CVE-2009-3546 gd: insufficient input validation in _gdGetColors()

Information

Published : 2009-10-19 20:00

Updated : 2023-12-10 10:51


NVD link : CVE-2009-3546

Mitre link : CVE-2009-3546

CVE.ORG link : CVE-2009-3546


JSON object : View

Products Affected

libgd

  • gd_graphics_library

php

  • php
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer