Medium severity5.3NVD Advisory· Published Jun 19, 2019· Updated Jun 17, 2026
CVE-2019-11038
CVE-2019-11038
Description
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
44- cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_desktop:12:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:sp4:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:suse:linux_enterprise_server:12:sp4:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp4:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp4:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp5:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:sp4:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:sp4:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:sp5:*:*:*:*:*:*
- Range: =2.2.5
- Range: <7.1.30, <7.2.19, <7.3.6
- osv-coords18 versionspkg:rpm/opensuse/gd&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/gd&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP1pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP4pkg:rpm/suse/gd&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4
< 2.2.5-lp151.6.6.1+ 17 more
- (no CPE)range: < 2.2.5-lp151.6.6.1
- (no CPE)range: < 2.3.3-1.1
- (no CPE)range: < 2.1.0-24.17.1
- (no CPE)range: < 2.2.5-4.14.1
- (no CPE)range: < 2.2.5-4.14.1
- (no CPE)range: < 2.2.5-4.14.1
- (no CPE)range: < 2.1.0-24.17.1
- (no CPE)range: < 2.1.0-24.17.1
- (no CPE)range: < 2.1.0-24.17.1
- (no CPE)range: < 2.1.0-24.17.1
- (no CPE)range: < 2.1.0-24.17.1
- (no CPE)range: < 2.1.0-24.17.1
- (no CPE)range: < 2.1.0-24.17.1
- (no CPE)range: < 2.1.0-24.17.1
- (no CPE)range: < 5.3.17-112.71.1
- (no CPE)range: < 5.3.17-112.71.1
- (no CPE)range: < 7.0.7-50.85.1
- (no CPE)range: < 7.0.7-50.85.1
Patches
Vulnerability mechanics
References
18- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- github.com/libgd/libgd/issues/501nvdExploitThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00020.htmlnvdMailing ListThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2519nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:3299nvdThird Party Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvdMailing ListThird Party Advisory
- bugs.php.net/bug.phpnvdVendor Advisory
- lists.debian.org/debian-lts-announce/2019/06/msg00003.htmlnvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2019/Sep/38nvdMailing ListThird Party Advisory
- usn.ubuntu.com/4316-1/nvdThird Party Advisory
- usn.ubuntu.com/4316-2/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4529nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4QQNDLBEMM6/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKSSWFR2WPMUOIB5EN5ZM252NNEPYUTG/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WAZBVK6XNYEIN7RDQXESSD63QHXPLKWL/nvd
News mentions
0No linked articles in our index yet.