Bugzilla – Bug 864878
VUL-0: CVE-2013-7328: php5: Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c
Last modified: 2015-03-30 15:09:39 UTC
CVE-2013-7328 Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allow remote attackers to cause a denial of service (application crash) or obtain sensitive information via an imagecrop function call with a negative value for the (1) x or (2) y dimension, a different vulnerability than CVE-2013-7226. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-7328 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7328 http://www.cvedetails.com/cve/CVE-2013-7328/
bugbot adjusting priority
(In reply to comment #0) > in PHP 5.5.x before 5.5.9 allow remote attackers to cause a denial of service We do not have such php anywhere.
yes, no gdimagecrop in SLE11 php 5.3.
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2015-04-13. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/61384