Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.
References
Configurations
History
No history.
Information
Published : 2007-09-04 18:17
Updated : 2017-09-29 01:29
NVD link : CVE-2007-3996
Mitre link : CVE-2007-3996
CVE.ORG link : CVE-2007-3996
JSON object : View
Products Affected
php
- php
CWE
CWE-189
Numeric Errors