#VU225 A read/write access error in gdImageTrueColorToPaletteBody() in PHP - CVE-2016-5114
Published: July 27, 2016 / Updated: August 13, 2016
PHP
PHP Group
Description
The vulnerability allows a remote attacker to disclose potentially sensitive information.
The vulnerability exists due to gdImageTrueColorToPaletteBody() function doesn't check for negative transparent colors while converting the image. A remote unauthenticated attacker can cause a read/write access error in gdImageTrueColorToPaletteBody().
Successful exploitation of this vulnerability may lead to arbitrary NULL-byte write and disclosure of potentially sensitive data.