NULL pointer dereference in PHP - CVE-2013-7327
Published: November 27, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return value. A remote attacker can trigger NULL pointer dereference via invalid imagecrop arguments and cause the service to crash.
Affected software
Gentoo Linux
Amazon Linux AMI
php5 (Ubuntu package)
php (Alpine package)
dev-lang/php
How to mitigate CVE-2013-7327
php5 (Ubuntu package) - addressed in versions 5.3.2-1ubuntu4.23, 5.3.10-1ubuntu3.10
php (Alpine package) - update to 5.5.11-r0
dev-lang/php - update to 5.5.16