CVE-2008-5498

Publication date 26 December 2008

Last updated 24 July 2024


Ubuntu priority

Negligible

Why this priority?

Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.

Read the notes from the security team

Status

Package Ubuntu Release Status
libgd2 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected
php5 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected

Notes


jdstrand

php5 on Ubuntu is linked against libgd2, which is not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
php5