Bug 863969 (CVE-2013-7226) - VUL-0: CVE-2013-7226: php5: Heap Overflow Vulnerability in imagecrop()
Summary: VUL-0: CVE-2013-7226: php5: Heap Overflow Vulnerability in imagecrop()
Status: RESOLVED FIXED
Alias: CVE-2013-7226
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Deadline: 2015-04-13
Assignee: Petr Gajdos
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/96189/
Whiteboard: maint:running:56329:important maint:r...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-02-14 09:43 UTC by Alexander Bergmann
Modified: 2019-06-17 22:47 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-02-14 09:43:27 UTC
A heap overflow vulnerability was found inside the PHP imagecrop() function. This could cause the execution of arbitrary code.

This has been corrected in PHP 5.5.9.

Upstream Fix:
http://git.php.net/?p=php-src.git;a=commitdiff;h=8f4a5373bb71590352fd934028d6dde5bc18530b

CVE-2013-7226 was assigned to this issue.

References:
https://bugs.php.net/bug.php?id=66356
http://www.php.net/ChangeLog-5.php#5.5.9
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-7226
https://bugzilla.redhat.com/show_bug.cgi?id=1065108
Comment 1 Swamp Workflow Management 2014-02-14 23:00:13 UTC
bugbot adjusting priority
Comment 2 Petr Gajdos 2014-02-17 08:26:35 UTC
Reading the bug report,

"All versions of PHP containing the imagecrop() function are vulnerable, i.e. PHP 5.5.0 and newer."

Factory has fixed 5.5.9, so sle12 remains.
Comment 4 Petr Gajdos 2014-02-17 09:50:37 UTC
Verified: 5.5.8 segfaults on i586 for all 4 POCs listed in bug, 5.5.9 no.
Comment 5 Petr Gajdos 2014-02-17 09:58:25 UTC
There's really not imagecrop() function in 5.4, 5.3 and 5.2, so POCs are void there.
Comment 6 Stefan Behlert 2014-02-17 15:17:13 UTC
I'd do an version update.
Comment 7 Petr Gajdos 2014-02-17 15:48:22 UTC
Done, thanks.
Comment 9 Swamp Workflow Management 2014-02-20 09:29:21 UTC
The SWAMPID for this issue is 56329.
This issue was rated as important.
Please submit fixed packages until 2014-02-27.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 10 SMASH SMASH 2014-02-20 09:30:15 UTC
Affected packages:

SLE-11-SP3: php53, php5
SLE-11-SP2: php53, php5
SLE-11-SP1: php5
SLE-10-SP3: php5
SLE-10-SP3-TERADATA: php5
Comment 11 Swamp Workflow Management 2014-02-20 12:19:21 UTC
The SWAMPID for this issue is 56343.
This issue was rated as important.
Please submit fixed packages until 2014-02-27.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 12 Marcus Meissner 2014-02-25 16:38:28 UTC
no imagecrop in sle11 php53.
Comment 13 Swamp Workflow Management 2015-03-30 15:08:29 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2015-04-13.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/61384