Description
Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2015-4600)
Magento CVE-2019-8229 Vulnerability (CVE-2019-8229)
WordPress Plugin Better WordPress Minify Arbitrary File Disclosure (1.2.2)
WebLogic CVE-2020-14638 Vulnerability (CVE-2020-14638)
MediaWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2020-35475)