Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.
References
Configurations
Information
Published : 2007-09-04 11:17
Updated : 2017-09-28 18:29
NVD link : CVE-2007-3996
Mitre link : CVE-2007-3996
JSON object : View
CWE
CWE-189
Numeric Errors
Products Affected
php
- php