Bugzilla – Bug 864879
VUL-0: CVE-2013-7327: php5: The gdImageCrop function in ext/gd/gd.c possible denial of service
Last modified: 2015-03-30 15:08:40 UTC
CVE-2013-7327 The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via invalid imagecrop arguments that lead to use of a NULL pointer as a return value, a different vulnerability than CVE-2013-7226. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-7327 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7327
bugbot adjusting priority
(In reply to comment #0) > The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not We do not have such php anywhere.
no gdImageCrop used in SLE11 php 5.3, yes.
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2015-04-13. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/61384