Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2014-9709

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.

  • Published: Mar 30, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-9709
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
php / php 5.5.0 5.5.21
php / php 5.6.0 5.6.5
php / php 5.4.0 5.4.40
opensuse / opensuse 13.1 13.1.x
opensuse / opensuse 13.2 13.2.x
libgd / libgd - 2.1.1.x
debian / debian_linux 8.0 8.0.x
debian / debian_linux 7.0 7.0.x
canonical / ubuntu_linux 12.04 12.04.x
canonical / ubuntu_linux 16.04 16.04.x
canonical / ubuntu_linux 15.10 15.10.x
canonical / ubuntu_linux 14.04 14.04.x