2018-07-23 04:06:44 -04:00
{
2019-03-17 23:36:37 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org" ,
"ID" : "CVE-2018-14553" ,
2020-02-11 13:01:14 +00:00
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a" ,
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
} ,
"vendor_name" : "n/a"
}
]
}
2019-03-17 23:36:37 +00:00
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2020-02-12 13:01:08 +00:00
"value" : "gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled)."
2020-02-11 13:01:14 +00:00
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "n/a"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1599032" ,
"refsource" : "MISC" ,
"name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1599032"
} ,
{
"refsource" : "MISC" ,
"name" : "https://github.com/libgd/libgd/pull/580" ,
"url" : "https://github.com/libgd/libgd/pull/580"
} ,
2020-02-12 13:01:08 +00:00
{
"refsource" : "MISC" ,
"name" : "https://github.com/libgd/libgd/commit/a93eac0e843148dc2d631c3ba80af17e9c8c860f" ,
"url" : "https://github.com/libgd/libgd/commit/a93eac0e843148dc2d631c3ba80af17e9c8c860f"
2020-02-18 04:01:04 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[debian-lts-announce] 20200218 [SECURITY] [DLA 2106-1] libgd2 security update" ,
"url" : "https://lists.debian.org/debian-lts-announce/2020/02/msg00014.html"
2020-03-11 01:01:11 +00:00
} ,
{
"refsource" : "SUSE" ,
"name" : "openSUSE-SU-2020:0332" ,
"url" : "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.html"
2020-03-31 02:01:14 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2020-e795f92d79" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/"
2020-04-04 00:01:34 +00:00
} ,
{
"refsource" : "UBUNTU" ,
"name" : "USN-4316-2" ,
"url" : "https://usn.ubuntu.com/4316-2/"
2020-04-08 02:01:15 +00:00
} ,
{
"refsource" : "UBUNTU" ,
"name" : "USN-4316-1" ,
"url" : "https://usn.ubuntu.com/4316-1/"
2019-03-17 23:36:37 +00:00
}
]
}
}