CVE-2019-6977 is a heap-based buffer overflow vulnerability in the gdImageColorMatch function of the GD Graphics Library (LibGD) 2.2.5, impacting PHP versions before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, as well as Canonical, Debian, and NetApp products. Rated 8.8 HIGH (CVSSv3), it allows unauthenticated attackers to achieve high confidentiality, integrity, and availability impacts with low attack complexity, requiring user interaction to trigger via crafted image data. While not on the KEV catalog and lacking Metasploit/Nuclei modules, an ExploitDB entry (EDB-46677) exists for PHP 7.2, indicating public exploit code availability, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.5CPE matchmatch criteria | cpe:2.3:a:libgd:libgd:2.2.5:*:*:*:*:*:*:* | ||
< 5.6.40CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.1.26CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 7.2.0, < 7.2.14CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
7.3.0CPE matchmatch criteria | cpe:2.3:a:php:php:7.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.