CVE-2010-4698

Stack-based buffer overflow in the GD extension in PHP before 5.2.15 and 5.3.x before 5.3.4 allows context-dependent attackers to cause a denial of service (application crash) via a large number of anti-aliasing steps in an argument to the imagepstext function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.2.2:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.2.3:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.2.4:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.2.10:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.2.11:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.2.12:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.2.13:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.2.14:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:21

Type Values Removed Values Added
References () http://bugs.php.net/53492 - () http://bugs.php.net/53492 -
References () http://marc.info/?l=bugtraq&m=133469208622507&w=2 - () http://marc.info/?l=bugtraq&m=133469208622507&w=2 -
References () http://seclists.org/fulldisclosure/2010/Dec/180 - () http://seclists.org/fulldisclosure/2010/Dec/180 -
References () http://www.php.net/ChangeLog-5.php - () http://www.php.net/ChangeLog-5.php -
References () http://www.securityfocus.com/bid/45338 - () http://www.securityfocus.com/bid/45338 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11939 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11939 -

Information

Published : 2011-01-18 20:00

Updated : 2024-11-21 01:21


NVD link : CVE-2010-4698

Mitre link : CVE-2010-4698

CVE.ORG link : CVE-2010-4698


JSON object : View

Products Affected

php

  • php
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer