Lucene search

K
hackeroneOrangeH1:305972
HistoryJan 17, 2018 - 5:27 p.m.

Internet Bug Bounty: Potential infinite loop in gdImageCreateFromGifCtx!

2018-01-1717:27:50
orange
hackerone.com
$500
43

0.002 Low

EPSS

Percentile

62.0%

Description


It is easy to trigger in web application if the web use GD as its image library.
For example, It can be triggered if a website resize the user-uploaded GIF, and ALL PHP version are affected!

Original bug report


Note


  • CVE-2018-5711 assigned

Thanks :)

Impact

A malicious GIF can trigger an infinite loop and lead to exhausted the server resource!