Description
The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Statistics Remote Code Execution (1.8)
Oracle Database Server CVE-2023-22073 Vulnerability (CVE-2023-22073)
Squid Improper Encoding or Escaping of Output Vulnerability (CVE-2021-28662)
PHP Other Vulnerability (CVE-2016-4541)
WordPress Plugin Featured Comments Cross-Site Request Forgery (1.2.1)