CVE-2018-5711

Source
Severity Medium
Remote Yes
Type Denial of service
Description
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.
Group Package Affected Fixed Severity Status Ticket
AVG-865 gd 2.2.5-1 Critical Vulnerable
References
https://lists.debian.org/debian-lts-announce/2019/01/msg00028.html
https://lists.debian.org/debian-lts-announce/2018/01/msg00022.html