#VU12348 Memory corruption in GD Graphics Library and PHP - CVE-2009-3546
Published: May 2, 2018
GD Graphics Library
PHP
Boutell.Com, Inc.
PHP Group
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in the _gdGetColors function in gd_gd.c due to improper verification of a certain colorsTotal structure member. A remote attacker can trick the victim into opening a specially crafted GD file, trigger buffer over-read or buffer overflow and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.