Out-of-bounds read in libgd - CVE-2019-11038
Published: September 23, 2019 / Updated: April 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD). A remote attacker can create a specially crafted image, pass it to the affected application, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Amazon Linux AMI
Slackware Linux
Opensuse
openEuler
Fedora
Red Hat Software Collections
IBM Cloud Pak for Security
IBM Cloud Pak for Business Automation
QRadar Suite
libgd2 (Ubuntu package)
php7.0 (Debian package)
php7 (Alpine package)
gd
php-process
php-pdo
php-soap
php-debuginfo
php-xmlrpc
php-recode
php-odbc
php-pgsql
php-devel
php-mbstring
php-snmp
php-bcmath
php-mysqlnd
php-help
php-fpm
php
php-gmp
php-json
php-tidy
php-common
php-intl
php-dba
php-xml
php-embedded
php-cli
php-enchant
php-dbg
php-opcache
php-debugsource
php-ldap
php-gd
Business Automation Insights
How to mitigate CVE-2019-11038
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
libgd2 (Ubuntu package) - addressed in versions 2.1.1-4ubuntu0.16.04.12, 2.2.5-4ubuntu0.4, 2.2.5-5.2ubuntu0.19.10.1
php7.0 (Debian package) - update to 7.0.33-0+deb9u5
php7 (Alpine package) - update to 7.1.32-r0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF004, 25.0.0
Business Automation Insights - update to 24.0.1.0.4
gd - update to 2.3.0-1.fc32
php-process - update to 7.2.10-19
php-pdo - update to 7.2.10-19
php-soap - update to 7.2.10-19
php-debuginfo - update to 7.2.10-19
php-xmlrpc - update to 7.2.10-19
php-recode - update to 7.2.10-19
php-odbc - update to 7.2.10-19
php-pgsql - update to 7.2.10-19
php-devel - update to 7.2.10-19
php-mbstring - update to 7.2.10-19
php-snmp - update to 7.2.10-19
php-bcmath - update to 7.2.10-19
php-mysqlnd - update to 7.2.10-19
php-help - update to 7.2.10-19
php-fpm - update to 7.2.10-19
php - update to 7.2.10-19
php-gmp - update to 7.2.10-19
php-json - update to 7.2.10-19
php-tidy - update to 7.2.10-19
php-common - update to 7.2.10-19
php-intl - update to 7.2.10-19
php-dba - update to 7.2.10-19
php-xml - update to 7.2.10-19
php-embedded - update to 7.2.10-19
php-cli - update to 7.2.10-19
php-enchant - update to 7.2.10-19
php-dbg - update to 7.2.10-19
php-opcache - update to 7.2.10-19
php-debugsource - update to 7.2.10-19
php-ldap - update to 7.2.10-19
php-gd - update to 7.2.10-19
php - addressed in versions 7.2.19-2.fc29, 7.3.6-1.fc30
External References
- https://access.redhat.com/errata/RHSA-2019:2519
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929821
- https://bugs.php.net/bug.php?id=77973
- https://bugzilla.redhat.com/show_bug.cgi?id=1724149
- https://bugzilla.redhat.com/show_bug.cgi?id=1724432
- https://bugzilla.suse.com/show_bug.cgi?id=1140118
- https://bugzilla.suse.com/show_bug.cgi?id=1140120
- https://github.com/libgd/libgd/issues/501
- https://lists.debian.org/debian-lts-announce/2019/06/msg00003.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKSSWFR2WPMUOIB5EN5ZM252NNEPYUTG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAZBVK6XNYEIN7RDQXESSD63QHXPLKWL/
Related Security Bulletins
- Debian update for php7.0
- Amazon Linux AMI update for php71, php72, php73
- Red Hat update for rh-php72-php
- Slackware Linux update for gd
- OpenSUSE Linux update for gd
- Ubuntu update for GD Graphics Library
- Out-of-bounds read in php7 (Alpine package)
- openEuler 20.03 LTS SP1 update for php
- Fedora 30 update for php
- Fedora 29 update for php
- Fedora 32 update for gd
- Multiple vulnerabilities in IBM Cloud Pak for Security and IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Business Automation Insights