CVE-2018-5711
Publication date 16 January 2018
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| php5 | ||
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| libgd2 | ||
| 20.04 LTS focal |
Fixed 2.2.5-4ubuntu1
|
|
| 18.04 LTS bionic |
Fixed 2.2.5-4ubuntu0.2
|
|
| php7.0 | ||
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| php7.1 | ||
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
Notes
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | Required |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | None |
| Availability impact | High |
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-3755-1
- GD vulnerabilities
- 27 August 2018