Out-of-bounds read in PHP - CVE-2014-9709
Published: March 30, 2015 / Updated: July 24, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5,. A remote attacker can perform a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
gd (Alpine package)
php74-sockets-debuginfo
php74-odbc-debuginfo
php74-sockets
php74-soap-debuginfo
php74-soap
php74-snmp-debuginfo
php74-snmp
php74-shmop-debuginfo
php74-shmop
php74-readline-debuginfo
php74-readline
php74-posix-debuginfo
php74-posix
php74-phar-debuginfo
php74-phar
php74-pgsql-debuginfo
php74-pgsql
php74-pdo-debuginfo
php74-pdo
php74-pcntl-debuginfo
php74-pcntl
php74-openssl-debuginfo
php74-openssl
php74-opcache-debuginfo
php74-opcache
php74-zlib-debuginfo
php74-tokenizer
php74-zlib
php74-zip-debuginfo
php74-zip
php74-xsl-debuginfo
php74-xsl
php74-xmlwriter-debuginfo
php74-xmlwriter
php74-xmlrpc-debuginfo
php74-xmlrpc
php74-xmlreader-debuginfo
php74-xmlreader
php74-tokenizer-debuginfo
php74-sodium
php74-tidy-debuginfo
php74-tidy
php74-sysvshm-debuginfo
php74-sysvshm
php74-sysvsem-debuginfo
php74-sysvsem
php74-sysvmsg-debuginfo
php74-sysvmsg
php74-sqlite-debuginfo
php74-sqlite
php74-sodium-debuginfo
php74-ctype
php74-fastcgi
php74-exif-debuginfo
php74-exif
php74-enchant-debuginfo
php74-enchant
php74-dom-debuginfo
php74-dom
php74-dba-debuginfo
php74-dba
php74-curl-debuginfo
php74-curl
php74-ctype-debuginfo
php74-fastcgi-debuginfo
php74-calendar-debuginfo
php74-calendar
php74-bz2-debuginfo
php74-bz2
php74-bcmath-debuginfo
php74-bcmath
php74
apache2-mod_php74-debuginfo
apache2-mod_php74
php74-devel
php74-debugsource
php74-debuginfo
php74-gmp-debuginfo
php74-mysql-debuginfo
php74-mysql
php74-mbstring-debuginfo
php74-mbstring
php74-ldap-debuginfo
php74-ldap
php74-json-debuginfo
php74-json
php74-intl-debuginfo
php74-intl
php74-iconv-debuginfo
php74-iconv
php74-odbc
php74-gmp
php74-gettext-debuginfo
php74-gettext
php74-gd-debuginfo
php74-gd
php74-ftp-debuginfo
php74-ftp
php74-fpm-debuginfo
php74-fpm
php74-fileinfo-debuginfo
php74-fileinfo
How to mitigate CVE-2014-9709
gd (Alpine package) - update to 2.1.1-r0
php74-sockets-debuginfo - update to 7.4.33-1.50.2
php74-odbc-debuginfo - update to 7.4.33-1.50.2
php74-sockets - update to 7.4.33-1.50.2
php74-soap-debuginfo - update to 7.4.33-1.50.2
php74-soap - update to 7.4.33-1.50.2
php74-snmp-debuginfo - update to 7.4.33-1.50.2
php74-snmp - update to 7.4.33-1.50.2
php74-shmop-debuginfo - update to 7.4.33-1.50.2
php74-shmop - update to 7.4.33-1.50.2
php74-readline-debuginfo - update to 7.4.33-1.50.2
php74-readline - update to 7.4.33-1.50.2
php74-posix-debuginfo - update to 7.4.33-1.50.2
php74-posix - update to 7.4.33-1.50.2
php74-phar-debuginfo - update to 7.4.33-1.50.2
php74-phar - update to 7.4.33-1.50.2
php74-pgsql-debuginfo - update to 7.4.33-1.50.2
php74-pgsql - update to 7.4.33-1.50.2
php74-pdo-debuginfo - update to 7.4.33-1.50.2
php74-pdo - update to 7.4.33-1.50.2
php74-pcntl-debuginfo - update to 7.4.33-1.50.2
php74-pcntl - update to 7.4.33-1.50.2
php74-openssl-debuginfo - update to 7.4.33-1.50.2
php74-openssl - update to 7.4.33-1.50.2
php74-opcache-debuginfo - update to 7.4.33-1.50.2
php74-opcache - update to 7.4.33-1.50.2
php74-zlib-debuginfo - update to 7.4.33-1.50.2
php74-tokenizer - update to 7.4.33-1.50.2
php74-zlib - update to 7.4.33-1.50.2
php74-zip-debuginfo - update to 7.4.33-1.50.2
php74-zip - update to 7.4.33-1.50.2
php74-xsl-debuginfo - update to 7.4.33-1.50.2
php74-xsl - update to 7.4.33-1.50.2
php74-xmlwriter-debuginfo - update to 7.4.33-1.50.2
php74-xmlwriter - update to 7.4.33-1.50.2
php74-xmlrpc-debuginfo - update to 7.4.33-1.50.2
php74-xmlrpc - update to 7.4.33-1.50.2
php74-xmlreader-debuginfo - update to 7.4.33-1.50.2
php74-xmlreader - update to 7.4.33-1.50.2
php74-tokenizer-debuginfo - update to 7.4.33-1.50.2
php74-sodium - update to 7.4.33-1.50.2
php74-tidy-debuginfo - update to 7.4.33-1.50.2
php74-tidy - update to 7.4.33-1.50.2
php74-sysvshm-debuginfo - update to 7.4.33-1.50.2
php74-sysvshm - update to 7.4.33-1.50.2
php74-sysvsem-debuginfo - update to 7.4.33-1.50.2
php74-sysvsem - update to 7.4.33-1.50.2
php74-sysvmsg-debuginfo - update to 7.4.33-1.50.2
php74-sysvmsg - update to 7.4.33-1.50.2
php74-sqlite-debuginfo - update to 7.4.33-1.50.2
php74-sqlite - update to 7.4.33-1.50.2
php74-sodium-debuginfo - update to 7.4.33-1.50.2
php74-ctype - update to 7.4.33-1.50.2
php74-fastcgi - update to 7.4.33-1.50.2
php74-exif-debuginfo - update to 7.4.33-1.50.2
php74-exif - update to 7.4.33-1.50.2
php74-enchant-debuginfo - update to 7.4.33-1.50.2
php74-enchant - update to 7.4.33-1.50.2
php74-dom-debuginfo - update to 7.4.33-1.50.2
php74-dom - update to 7.4.33-1.50.2
php74-dba-debuginfo - update to 7.4.33-1.50.2
php74-dba - update to 7.4.33-1.50.2
php74-curl-debuginfo - update to 7.4.33-1.50.2
php74-curl - update to 7.4.33-1.50.2
php74-ctype-debuginfo - update to 7.4.33-1.50.2
php74-fastcgi-debuginfo - update to 7.4.33-1.50.2
php74-calendar-debuginfo - update to 7.4.33-1.50.2
php74-calendar - update to 7.4.33-1.50.2
php74-bz2-debuginfo - update to 7.4.33-1.50.2
php74-bz2 - update to 7.4.33-1.50.2
php74-bcmath-debuginfo - update to 7.4.33-1.50.2
php74-bcmath - update to 7.4.33-1.50.2
php74 - update to 7.4.33-1.50.2
apache2-mod_php74-debuginfo - update to 7.4.33-1.50.2
apache2-mod_php74 - update to 7.4.33-1.50.2
php74-devel - update to 7.4.33-1.50.2
php74-debugsource - update to 7.4.33-1.50.2
php74-debuginfo - update to 7.4.33-1.50.2
php74-gmp-debuginfo - update to 7.4.33-1.50.2
php74-mysql-debuginfo - update to 7.4.33-1.50.2
php74-mysql - update to 7.4.33-1.50.2
php74-mbstring-debuginfo - update to 7.4.33-1.50.2
php74-mbstring - update to 7.4.33-1.50.2
php74-ldap-debuginfo - update to 7.4.33-1.50.2
php74-ldap - update to 7.4.33-1.50.2
php74-json-debuginfo - update to 7.4.33-1.50.2
php74-json - update to 7.4.33-1.50.2
php74-intl-debuginfo - update to 7.4.33-1.50.2
php74-intl - update to 7.4.33-1.50.2
php74-iconv-debuginfo - update to 7.4.33-1.50.2
php74-iconv - update to 7.4.33-1.50.2
php74-odbc - update to 7.4.33-1.50.2
php74-gmp - update to 7.4.33-1.50.2
php74-gettext-debuginfo - update to 7.4.33-1.50.2
php74-gettext - update to 7.4.33-1.50.2
php74-gd-debuginfo - update to 7.4.33-1.50.2
php74-gd - update to 7.4.33-1.50.2
php74-ftp-debuginfo - update to 7.4.33-1.50.2
php74-ftp - update to 7.4.33-1.50.2
php74-fpm-debuginfo - update to 7.4.33-1.50.2
php74-fpm - update to 7.4.33-1.50.2
php74-fileinfo-debuginfo - update to 7.4.33-1.50.2
php74-fileinfo - update to 7.4.33-1.50.2
External References
- http://advisories.mageia.org/MGASA-2015-0040.html
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00005.html
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00002.html
- http://marc.info/?l=bugtraq&m=143403519711434&w=2
- http://php.net/ChangeLog-5.php
- http://rhn.redhat.com/errata/RHSA-2015-1053.html
- http://rhn.redhat.com/errata/RHSA-2015-1066.html
- http://rhn.redhat.com/errata/RHSA-2015-1135.html
- http://rhn.redhat.com/errata/RHSA-2015-1218.html
- http://www.debian.org/security/2015/dsa-3215
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:153
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.securityfocus.com/bid/73306
- http://www.securitytracker.com/id/1033703
- http://www.ubuntu.com/usn/USN-2987-1
- https://bitbucket.org/libgd/gd-libgd/commits/47eb44b2e90ca88a08dca9f9a1aa9041e9587f43
- https://bugs.php.net/bug.php?id=68601
- https://bugzilla.redhat.com/show_bug.cgi?id=1188639
- https://security.gentoo.org/glsa/201606-10
- https://security.gentoo.org/glsa/201607-04
- https://support.apple.com/HT205267