gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-01-16T09:00:00

Updated: 2024-08-05T05:40:51.271Z

Reserved: 2018-01-16T00:00:00

Link: CVE-2018-5711

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-01-16T09:29:00.577

Modified: 2023-11-07T02:58:49.180

Link: CVE-2018-5711

cve-icon Redhat

Severity : Low

Publid Date: 2017-11-25T00:00:00Z

Links: CVE-2018-5711 - Bugzilla