Out-of-bounds read in libgd - CVE-2019-11038

 

Out-of-bounds read in libgd - CVE-2019-11038

Published: September 23, 2019 / Updated: April 3, 2020


Vulnerability identifier: #VU21274
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11038
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD). A remote attacker can create a specially crafted image, pass it to the affected application, trigger out-of-bounds read error and read contents of memory on the system.




Affected software

libgd
Amazon Linux AMI
Slackware Linux
Opensuse
openEuler
Fedora
Red Hat Software Collections
IBM Cloud Pak for Security
IBM Cloud Pak for Business Automation
QRadar Suite
libgd2 (Ubuntu package)
php7.0 (Debian package)
php7 (Alpine package)
gd
php-process
php-pdo
php-soap
php-debuginfo
php-xmlrpc
php-recode
php-odbc
php-pgsql
php-devel
php-mbstring
php-snmp
php-bcmath
php-mysqlnd
php-help
php-fpm
php
php-gmp
php-json
php-tidy
php-common
php-intl
php-dba
php-xml
php-embedded
php-cli
php-enchant
php-dbg
php-opcache
php-debugsource
php-ldap
php-gd
Business Automation Insights

How to mitigate CVE-2019-11038

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

libgd - update to 2.3.0
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
libgd2 (Ubuntu package) - addressed in versions 2.1.1-4ubuntu0.16.04.12, 2.2.5-4ubuntu0.4, 2.2.5-5.2ubuntu0.19.10.1
php7.0 (Debian package) - update to 7.0.33-0+deb9u5
php7 (Alpine package) - update to 7.1.32-r0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF004, 25.0.0
Business Automation Insights - update to 24.0.1.0.4
gd - update to 2.3.0-1.fc32
php-process - update to 7.2.10-19
php-pdo - update to 7.2.10-19
php-soap - update to 7.2.10-19
php-debuginfo - update to 7.2.10-19
php-xmlrpc - update to 7.2.10-19
php-recode - update to 7.2.10-19
php-odbc - update to 7.2.10-19
php-pgsql - update to 7.2.10-19
php-devel - update to 7.2.10-19
php-mbstring - update to 7.2.10-19
php-snmp - update to 7.2.10-19
php-bcmath - update to 7.2.10-19
php-mysqlnd - update to 7.2.10-19
php-help - update to 7.2.10-19
php-fpm - update to 7.2.10-19
php - update to 7.2.10-19
php-gmp - update to 7.2.10-19
php-json - update to 7.2.10-19
php-tidy - update to 7.2.10-19
php-common - update to 7.2.10-19
php-intl - update to 7.2.10-19
php-dba - update to 7.2.10-19
php-xml - update to 7.2.10-19
php-embedded - update to 7.2.10-19
php-cli - update to 7.2.10-19
php-enchant - update to 7.2.10-19
php-dbg - update to 7.2.10-19
php-opcache - update to 7.2.10-19
php-debugsource - update to 7.2.10-19
php-ldap - update to 7.2.10-19
php-gd - update to 7.2.10-19
php - addressed in versions 7.2.19-2.fc29, 7.3.6-1.fc30

External References

Related Security Bulletins