CVE-2019-11038 Details
Description
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-908 | Use of Uninitialized Resource | [email protected] |
| CWE-457 | Use of Uninitialized Variable | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libgd libgd | 2.2.5 |
CPE
Remediation
| |
| php php | >= 7.1.0, < 7.1.30 >= 7.2.0, < 7.2.19 >= 7.3.0, < 7.3.6 |
CPE
Remediation
| |
| canonical ubuntu linux | 14.04 16.04 18.04 19.10 |
CPE
Remediation
| |
| debian debian linux | 8.0 9.0 |
CPE
Remediation
| |
| fedoraproject fedora | 29 30 32 |
CPE
Remediation
| |
| suse linux enterprise debuginfo | 11 sp4 |
CPE
Remediation
| |
| opensuse leap | 15.1 |
CPE
Remediation
| |
| suse linux enterprise desktop | 12 sp4 |
CPE
Remediation
| |
| suse linux enterprise server | 12 sp4 12 sp5 |
CPE
Remediation
| |
| suse linux enterprise software development kit | 12 sp4 12 sp5 |
CPE
Remediation
| |
| suse linux enterprise workstation extension | 12 sp4 12 sp5 |
CPE
Remediation
| |
| redhat software collections | 1.0 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 16, 2020 | Modified Analysis | [email protected] |
| Apr 8, 2020 | CVE Modified | [email protected] |
| Apr 4, 2020 | CVE Modified | [email protected] |
| Mar 31, 2020 | CVE Modified | [email protected] |
| Mar 11, 2020 | CVE Modified | [email protected] |
| Nov 1, 2019 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Sep 23, 2019 | CVE Modified | [email protected] |
| Aug 19, 2019 | CVE Modified | [email protected] |
| Aug 15, 2019 | CVE Modified | [email protected] |
| Aug 15, 2019 | CVE Modified | [email protected] |
| Jun 20, 2019 | Initial Analysis | [email protected] |